Live data from Hacker News

YubiKey 4C

yubico.com

61–70 of 266 posts

Re: YubiKey 4C

#61

Do they work any better on iPhones? ----- I decided couple of months ago to secure entire family. Bought half dozen Neos, worked out all the kinks on my computer + Android phone first, put everything in LastPass (I know, I know, I know... but you have to consider the target audience ;).... only to discover on "go-live" that my wife's iPhone 6s is bloody useless with the thing. Apparently iPhone doesn't fully grok NFC…

Apple decided that users cannot use the NFC chip in it except for Apple Pay (for the foreseeable future). You don't really 'own' an Iphone in that sense.

Seriously?

Re: YubiKey 4C

#63

I have a Yubikey, but almost never use it. I still don't get it fully, don't have a use-case where it totally works for me. Having one key is maybe part of the problem. If I lose it, what then?

Most applications let you download backup codes for the event where you lose a key. But it's an anxiety I have as well.

Re: YubiKey 4C

#64

I have a Yubikey, but almost never use it. I still don't get it fully, don't have a use-case where it totally works for me. Having one key is maybe part of the problem. If I lose it, what then?

Some people will tell you to buy two Yubikeys and leave one as a backup. I don't think that's necessary. No matter what, you should generate a backup software key and keep it on offline encrypted storage; if you lose the token, just use the backup key until your replacement arrives.

It's even easier for Github and Google Mail. For web services, the right stack is:

* Hardware U2F token

* Backup software TOTP (Duo or Google Authenticator or whatever)

* Backup printed (or saved on offline USB key) passcodes

* Disabled SMS.

Unlike SMS, which is devastating to security even as a fallback, having a software TOTP option is basically fine; most of what U2F buys you is unphishability. This leaves you with two levels of backup, one of which is reasonably secure indefinitely.

Re: YubiKey 4C

#65
post #43
post #19

alternative is u2fzero, available on amazon for 8$, and totally open source. the difference is that yubi uses an nxp secure coprocessor, whereas the u2fzero uses atmel. there is the possibility of side-channel attacks on the u2fzero. but for your family, it is better than nothing and much more cost effective.

u2fzero is "Currently unavailable" on amazon. And the lack of housing makes me question how durable the device would be. The last thing I want is my u2f dying and locking me out of a ton of accounts.

I've had one on my keychain for a while. It's rugged enough for day to day use.

The only issue is that the hole for the key ring has a thin wall, so I have a plastic coated keyring to prevent the metal from rubbing the hole.

Re: YubiKey 4C

#66

Do any of these RSA alternatives have an LCD display showing the id? Our work computers are locked down and USB is not an option.

The OTP functions basically as a USB HID keyboard. So you can plug it into something that is not locked down (like a phone or tablet), and then just copy the code.

The drawback is that the code could be long. A few years ago, the codes were just 6 digits. My latest nano spits out a very long (20 char?) alpha-numeric string.

Re: YubiKey 4C

#67

Earlier quoted context omitted.

Apple decided that users cannot use the NFC chip in it except for Apple Pay (for the foreseeable future). You don't really 'own' an Iphone in that sense.

Seriously?

Found these as confirmation, based on Freak_NL's pointer; by design, NFC is used for a single purpose on iPhone 6 & 7 currently.

Will Apple support NFC tags in iOS 10 for the iPhone 7? :

https://gototags.com/blog/will-apple-finally-support-nfc-tag...

https://gototags.com/blog/apple-iphone-7-support-nfc-tags/

Re: YubiKey 4C

#68
post #47

I don't think that the people complaining about the price of this key appreciate all that it can do. Most of those people would probably be better off with the cheaper FIDO U2F Security Key. I haven't found anything else that manages RSA Keys, TOTP auth and U2F in a single package. I'm going to buy this because it plugs into my pixel phone and it seems like it'd be more secure and convenient than my current Neo with…

Annoying nerd pedantry: It's only sort of doing TOTP (Yubikeys don't have batteries, so need a software client to provide the clock), and on a slack with almost 300 crypto nerds in it, I don't know any of them that use the Y4 for TOTP (I'm preparing myself to be surprised in a minute when someone there reads this). TOTP is something you do on your phone.

Re: YubiKey 4C

#69
post #58

Note that this isn't just a U2F key; if you're looking for a token principally to log into web services with, this isn't what you want, and the token that does that costs less than half as much (it's the U2F-only token). You want a Y4 if: * You SSH into sensitive machines. * You log into a VPN that you control and can configure to use the Y4. * You're actually relying on PGP.

Bitcoin wallet security. That's the next big thing.

Re: YubiKey 4C

#70
post #22

Until there's a YubiKey 4C nano, I'll wait. Having something of that size sticking out of my computer is not really practical. Not having it inserted defeats the whole point.

This isn't something you should leave plugged in. It's a key after all used for authentication. Keep it on your keychain or in your wallet and plug in as needed.
Post reply on HN