Earlier quoted context omitted.
The yubikey neo support NFC. Comparison here: https://www.yubico.com/products/yubikey-hardware/ (Edited my comment to correct a mistake)
The only one that supports it appears to be an outdated model that isn't undergoing the latest certifications and lacks other features (like ECC p384)
Google Determines that FIDO U2F Security Keys Improve Security
51–60 of 69 posts
Re: Google Determines that FIDO U2F Security Keys Improve Security
#52Earlier quoted context omitted.
OK...but Google and my bank still use OTP over SMS to two-factor authenticate me. So clearly there's room for discussion and evangelism here. NIST can say that pigs fly, but until I see it in the wild I'm going to take it with a grain of salt.
Just so you know, you can also use Google Authenticator if you really dislike SMS. Make sure to back up those emergency keys though, and read about encrypting your iTunes backups so it'll actually back up the GA settings.
Re: Google Determines that FIDO U2F Security Keys Improve Security
#53How can I use U2F for Windows sign-on? Windows 10 "Hello" stuff is apparently in the pipeline, but I need U2F domain authentication for Windows 7+. Also curious if I can use a U2F for anything PGP-related, signing or encrypting regular stuff. All this to save $20/piece!
You can! This works mostly out of the box if you enable it using the manager application (looks like newer models may have it on by default) and install the required gpg smartcard stuff.
https://www.yubico.com/support/knowledge-base/categories/art...
Re: Google Determines that FIDO U2F Security Keys Improve Security
#54How can I use U2F for Windows sign-on? Windows 10 "Hello" stuff is apparently in the pipeline, but I need U2F domain authentication for Windows 7+. Also curious if I can use a U2F for anything PGP-related, signing or encrypting regular stuff. All this to save $20/piece!
> Also curious if I can use a U2F for anything PGP-related, signing or encrypting regular stuff. You can! This works mostly out of the box if you enable it using the manager application (looks like newer models may have it on by default) and install the required gpg smartcard stuff. https://www.yubico.com/support/knowledge-base/categories/art...
Thanks for pointing this info out though!
Re: Google Determines that FIDO U2F Security Keys Improve Security
#55And the actual study: http://fc16.ifca.ai/preproceedings/25_Lang.pdf
(Which helps answer some of the arguments in the discussion thus far. In particular, on page 11, they list the systems they compare against: SMS OTP, Google phone-based OTP, and three hardware tokens, including the FIDO U2F. They compare in Figure 6 explicitly with SMS OTP and app-based OTP.)
Re: Google Determines that FIDO U2F Security Keys Improve Security
#56Earlier quoted context omitted.
Partial quoting an article to the go on to disagree with the core premise and good security will net you no sympathy from me. But the burden is on you to update it make it clear what you're referring to. If you think that this is truly unfair then I apologize for only reading your post and the linked article and not the entire historical context. But I think even without that, you went on to make a point counter the…
Partial quoting? I quoted the relevant bit. I may as well accuse you of partial quoting too since you "only" quoted one sentence and not the surrounding sentences. > But the burden is on you to update it make it clear what you're referring to. Not when I can't edit the comment anymore. When I edited my comment to say the title has been changed, the title had just been changed to say "SMS OTP" instead of "OTP", so it…
So no. Absolutely not. SMS is an additional problem, but OTPs in general suffer from logistic issues separate from their medium.
Re: Google Determines that FIDO U2F Security Keys Improve Security
#57Earlier quoted context omitted.
You also need to have the password database. Having the master password alone is not sufficient, and having the password database is not sufficient. And of course the master password never gets transmitted over the network, so it's harder to get. If your threat model is an attacker that's compromised your specific computer (as opposed to a network attacker) then yeah, having the OTP code in your password manager isn'…
If all the factors are on the same box, it's just one factor.
So no, the two factors are not on the same box being attacked, in the threat modes of interest.
For the threat of "my stuff was stolen" then both factors are in the same box, so even having a separate piece of hardware is no use (unless you can convince the thief to not take everything and please leave the authenticator dongle behind).
Re: Google Determines that FIDO U2F Security Keys Improve Security
#58Earlier quoted context omitted.
OK...but Google and my bank still use OTP over SMS to two-factor authenticate me. So clearly there's room for discussion and evangelism here. NIST can say that pigs fly, but until I see it in the wild I'm going to take it with a grain of salt.
Just so you know, you can also use Google Authenticator if you really dislike SMS. Make sure to back up those emergency keys though, and read about encrypting your iTunes backups so it'll actually back up the GA settings.
Re: Google Determines that FIDO U2F Security Keys Improve Security
#59Earlier quoted context omitted.
What's preventing USB-C Yubikeys? So you need an adapter right now...
Apparently, lack of market demand [0]. As for adapters: they significantly increase the profile of the yubikey nano, which I feel is a dealbreaker in that particular case, as the main selling point of the nano (to me, at least) is the always-plugged-in capability (see the image on the far right in [1]). [0] https://www.yubico.com/2016/07/yubikey-route-usb-c/ [1] https://www.yubico.com/products/yubikey-hardware/yubike…
Re: Google Determines that FIDO U2F Security Keys Improve Security
#60Then again, maybe the recent Bluetooth 5 announcement will be enough to drive adoption. Or possibly the next iPhone / Pixel could act as a U2F device. Maybe then we could get "normal" people to use real security instead of asking them what street they grew up on or what their mother's maiden name is.