Live data from Hacker News

Security Key for safer logins with a touch

facebook.com

61–70 of 105 posts

Re: Security Key for safer logins with a touch

#61
post #36

I've been a big fan of yubikeys for years, but I'd never use mine for something like Facebook. I work in computer security, so I know this sounds crazy. But my brain has been rewired to work in failure modes by the not-security domain I happen to do security stuff in. The obvious argument for TFA is to reduce the chances that my Facebook account is subject to the bad consequences of that come from a compromised Faceb…

Has someone else read this and understood the argument? Because I don't follow it.

I agree.

It seems as though the same thing could be said for having any password at all on a Facebook account?

Re: Security Key for safer logins with a touch

#62

I'm happy with Authy and TOTP, for the moment. Getting a YubiKey has been on my to-do list for awhile, but I'm not sure that everything I currently have 2FA for will accept it. In which case, I don't like the idea of half-migrating to Yubikey while still having to keep Authenticator around.

You can use your Yubikey + Yubico Authenticater to replace Authy. It does not add that much security, but you add device switch ability without Cloud Sync.

Re: Security Key for safer logins with a touch

#63
post #40

Earlier quoted context omitted.

This is really awful, for it to work well you would need to buy multiple keys and each time use them all to register (which precludes the option of storing the backup key somewhere safe). Straight from the yubico website: "It is recommended that users register at least two U2F devices with every service provider should a U2F device be misplaced" That's just a plain usability nightmare, and not to mention expensive. T…

Part of the point of hardware tokens is that you can't back up and restore their keys. If backup and restore is important to your userbase, you should stick with soft tokens.

Can you recommend any soft token U2F implementation, especially if there's different "best" ones per-platform?

Re: Security Key for safer logins with a touch

#64
post #56

Earlier quoted context omitted.

Huh? I use the Google applications --- and, particularly, their calendar --- all the time without using Chrome, and U2F is my first-priority 2FA mechanism. You can mint static random application keys for your native applications, and use TOTP as a backup for when you want to use a different browser (really, though, you should use Chrome as much as you can; it's significantly more secure).

For some reason application passwords don't seem to work according to everyone who tried. I don't really know what TOTP is or how all of this is configured, that's the domain of our security team. I don't really know what you mean about Google apps, I just want to use the calendar app on my Mac and iPhone to see my meetings but I can't. I asked them about it and they confirmed to me that I should use the Google Calen…

In the Google security setting you can create new App-Passwords, use those in your Apple Mail or whatever. It should work fine.

Re: Security Key for safer logins with a touch

#65
post #64

Earlier quoted context omitted.

For some reason application passwords don't seem to work according to everyone who tried. I don't really know what TOTP is or how all of this is configured, that's the domain of our security team. I don't really know what you mean about Google apps, I just want to use the calendar app on my Mac and iPhone to see my meetings but I can't. I asked them about it and they confirmed to me that I should use the Google Calen…

In the Google security setting you can create new App-Passwords, use those in your Apple Mail or whatever. It should work fine.

If only a comment on Hacker News saying something should work made it so :)

Re: Security Key for safer logins with a touch

#66
post #57
post #44

Earlier quoted context omitted.

You can, but is there a way to do it such that Facebook won't under any circumstances send an SMS message?

Good question. I am not sSure you can do it without using SMS to bootstrap the process, but if you have TOTP set up and then turn on U2F (with TOTP as the backup) then I think you can disable SMS messages.

Either I'm dumb, or if that's true it's only true since they added U2F today.

(It's very possible that I'm dumb!)

Re: Security Key for safer logins with a touch

#68

Earlier quoted context omitted.

That's why you buy two keys. No, they don't have anything to "sync".

One issue with buying two keys is they internally have different keys, so you need to connect both to each new account which is a pain in the ass and stops you just keeping one somewhere very safe (i.e. safety deposit box, or a safe at a friends house)

Hopefully this will be addressed in FIDO 2.0. That is the goal at least.

Re: Security Key for safer logins with a touch

#69
post #66
post #57

Earlier quoted context omitted.

Good question. I am not sSure you can do it without using SMS to bootstrap the process, but if you have TOTP set up and then turn on U2F (with TOTP as the backup) then I think you can disable SMS messages.

Either I'm dumb, or if that's true it's only true since they added U2F today. (It's very possible that I'm dumb!)

So digging around a bit on the page the 'Learn More' in the login approvals (https://www.facebook.com/help/148233965247823) claims that you can turn off SMS codes, but I no longer have the advantage of being able to walk over a few desks to get a real verification :) I may try to set up U2F later today and see if this actually works...

You would also need to turn off login notifications (section just above login approvals in the security settings page.)

Re: Security Key for safer logins with a touch

#70

I am slightly disappointed that this doesn't work in Firefox, despite the fact that I have an add-on[1] installed to add U2F support. Github for instance is able to detect U2F support and let me use it. That said, I understand the lack of support since I am an extremely small niche, and this did prompt me to finally add 2FA to facebook (U2F and code generation from my Yubikey Neo) [1] https://addons.mozilla.org/en-US…

Firefox will be supported after they land support in release builds.
Post reply on HN