Live data from Hacker News

YubiKey 4C

yubico.com

71–80 of 266 posts

Re: YubiKey 4C

#71
post #58

Note that this isn't just a U2F key; if you're looking for a token principally to log into web services with, this isn't what you want, and the token that does that costs less than half as much (it's the U2F-only token). You want a Y4 if: * You SSH into sensitive machines. * You log into a VPN that you control and can configure to use the Y4. * You're actually relying on PGP.

But it's identical functionality to a Yubikey 4, just with type-C connector, and the product page as well as myself personally can verify that Yubikey 4 supports U2F

Re: YubiKey 4C

#72
post #48

I have a Yubikey, but almost never use it. I still don't get it fully, don't have a use-case where it totally works for me. Having one key is maybe part of the problem. If I lose it, what then?

When I first got mine, I was the same way. I learned different bits in steps. First was yubikey-luks for full disk encryption. Then using my ssh key on it. Then GPG key on it. Then using GPG key for password storage with QTPass, OpenKeychain/Android Password Store. Then 2FA with gmail. I'm getting a lot more use out of mine more than a year after originally getting it.

For the ssh key, are you using your yubikey on multiple computers or just one? I just started looking at this but it seems like there is a bit of setup needed for each computer. I guess it might be worth it but would be interested to hear about others experiences.

Re: YubiKey 4C

#73
post #40
post #22

Until there's a YubiKey 4C nano, I'll wait. Having something of that size sticking out of my computer is not really practical. Not having it inserted defeats the whole point.

I'm kind of wondering what the benefit is over having something like Yubikey at all instead of something that's just software when you just leave it in all the time.

Your computer can in theory get owned up without you losing your SSH or VPN keys, even if your keystrokes are logged.

Re: YubiKey 4C

#74
post #58

Note that this isn't just a U2F key; if you're looking for a token principally to log into web services with, this isn't what you want, and the token that does that costs less than half as much (it's the U2F-only token). You want a Y4 if: * You SSH into sensitive machines. * You log into a VPN that you control and can configure to use the Y4. * You're actually relying on PGP.

But it's identical functionality to a Yubikey 4, just with type-C connector, and the product page as well as myself personally can verify that Yubikey 4 supports U2F

I'm not saying the 4C doesn't do U2F. It's the same as the 4. I'm saying that if all you want to do is log into web services, you probably don't want the Y4.

Re: YubiKey 4C

#75
post #40
post #22

Until there's a YubiKey 4C nano, I'll wait. Having something of that size sticking out of my computer is not really practical. Not having it inserted defeats the whole point.

I'm kind of wondering what the benefit is over having something like Yubikey at all instead of something that's just software when you just leave it in all the time.

You can compromise software on a PC. You can't do that, as much, with a hardware key used for 2 factor authentication.

Re: YubiKey 4C

#76
post #35
post #22

Until there's a YubiKey 4C nano, I'll wait. Having something of that size sticking out of my computer is not really practical. Not having it inserted defeats the whole point.

Do you have to leave it plugged in to your computer the entire time? or just times you need 2FA?

You only plug it in when logging in.

Re: YubiKey 4C

#77
post #3

Why are Yubikeys so expensive? I have one and use them but the price always gets in the way of having more.

For something that authenticates you for 2 factor, I'd pay a lot more. After all, this is your key you use daily for the services you live off of. The value is a no brainer.

Re: YubiKey 4C

#78
post #22

Until there's a YubiKey 4C nano, I'll wait. Having something of that size sticking out of my computer is not really practical. Not having it inserted defeats the whole point.

Why do you need to keep it in? I have the blue U2f key and it's much larger. I just keep it on my keychain and only insert it while signing into something that requires it.

Re: YubiKey 4C

#79
post #4

I still don't get how people are ok using these things without a fingerprint reader...

You should turn off your fingerprint readers. Courts the world over are starting to agree with law enforcement that they have the right to take your fingerprints, and they have the right to do whatever they want with those fingerprints short of disclosing them to the public.

Sooooo... fingerprint auth is a useless security measure even for normal citizens.

Re: YubiKey 4C

#80
post #64

I have a Yubikey, but almost never use it. I still don't get it fully, don't have a use-case where it totally works for me. Having one key is maybe part of the problem. If I lose it, what then?

Some people will tell you to buy two Yubikeys and leave one as a backup. I don't think that's necessary. No matter what, you should generate a backup software key and keep it on offline encrypted storage; if you lose the token, just use the backup key until your replacement arrives. It's even easier for Github and Google Mail. For web services, the right stack is: * Hardware U2F token * Backup software TOTP (Duo or G…

Isn't disabled SMS overkill for most casual thread models? As I understand it SMS would require someone to MITM the telecom network OR snoop the local antenna when you receive it on your phone. Which is a danger if you expect, like, nation-state adversaries.

But if I'm, say, protecting my GitHub account against Russian mafia hackers, that still seems perfectly fine?

Post reply on HN