Live data from Hacker News

YubiKey 4C

yubico.com

41–50 of 266 posts

Re: YubiKey 4C

#41
I have a Yubikey, but almost never use it. I still don't get it fully, don't have a use-case where it totally works for me. Having one key is maybe part of the problem. If I lose it, what then?

Re: YubiKey 4C

#42

Kind of useless to have a C-only device this early. An A/C-hybrid would be much more useful, like Kingston's MicroDuo[1] series. [1]: http://www.kingston.com/us/usb/personal_business/DTDUO3C

..or from YubiKey for 1$ more (then their USB c version)

https://www.yubico.com/product/yubikey-4-nano-usbc-bundle/

Re: YubiKey 4C

#43
post #19

alternative is u2fzero, available on amazon for 8$, and totally open source. the difference is that yubi uses an nxp secure coprocessor, whereas the u2fzero uses atmel. there is the possibility of side-channel attacks on the u2fzero. but for your family, it is better than nothing and much more cost effective.

u2fzero is "Currently unavailable" on amazon. And the lack of housing makes me question how durable the device would be. The last thing I want is my u2f dying and locking me out of a ton of accounts.

Re: YubiKey 4C

#45
post #5

Earlier quoted context omitted.

Wouldn't that make it 3FA? I'd need my password, my physical key and my fingerprints?

One could then argue the Google Authenticator app running on my iPhone is 3FA, as one needs to be able to unlock my iPhone to access it.

I would definitely argue that it's 3FA.

* Something you know - the service's password

* Something you have - the phone with the authenticator

* Something you are - your fingerprint

EDITED - formatting

Re: YubiKey 4C

#46
post #38
post #19

alternative is u2fzero, available on amazon for 8$, and totally open source. the difference is that yubi uses an nxp secure coprocessor, whereas the u2fzero uses atmel. there is the possibility of side-channel attacks on the u2fzero. but for your family, it is better than nothing and much more cost effective.

You have a link? The only thing I get for u2fzero is their site with instructions on how to build one.

Closest I could find that was still available is

https://amazon.com/HyperFido-K5-FIDO-U2F-Security/dp/B00WIX4...

Re: YubiKey 4C

#47
I don't think that the people complaining about the price of this key appreciate all that it can do. Most of those people would probably be better off with the cheaper FIDO U2F Security Key.

I haven't found anything else that manages RSA Keys, TOTP auth and U2F in a single package. I'm going to buy this because it plugs into my pixel phone and it seems like it'd be more secure and convenient than my current Neo with NFC.

Re: YubiKey 4C

#48

I have a Yubikey, but almost never use it. I still don't get it fully, don't have a use-case where it totally works for me. Having one key is maybe part of the problem. If I lose it, what then?

When I first got mine, I was the same way. I learned different bits in steps. First was yubikey-luks for full disk encryption. Then using my ssh key on it. Then GPG key on it. Then using GPG key for password storage with QTPass, OpenKeychain/Android Password Store. Then 2FA with gmail. I'm getting a lot more use out of mine more than a year after originally getting it.

Re: YubiKey 4C

#49

Kind of useless to have a C-only device this early. An A/C-hybrid would be much more useful, like Kingston's MicroDuo[1] series. [1]: http://www.kingston.com/us/usb/personal_business/DTDUO3C

Could you explain why you think that? The audience for this is people that primarily use C-only devices; it was requested by customers.

I don't see the point of a dual device except to add size and expense. I'd rather just go with a dongle, as it can be reused.

Re: YubiKey 4C

#50
post #22

Until there's a YubiKey 4C nano, I'll wait. Having something of that size sticking out of my computer is not really practical. Not having it inserted defeats the whole point.

> Not having it inserted defeats the whole point How so? I would keep this on a keychain or lanyard (it looks rugged enough to handle that sort of environment). When I need to authenticate, I plug it in, when I'm done, I unplug it. That seems a lot more secure than leaving it in the computer all the time. If someone gets my computer and the YubiKey is always installed, that sort of defeats the purpose of having a sep…

I've had the standard USB version on my keys for about a year at this point. They're in my back pocket and take a bunch of abuse. Still works just fine.
Post reply on HN