Live data from Hacker News

YubiKey 4C

yubico.com

81–90 of 266 posts

Re: YubiKey 4C

#81

Remember that closed source security-related products are a complete joke and you should spend your money somewhere else.

Any suggestions?

Just use a TOTP app, at the moment. Note that because there are no U2F alternatives means that you shouldn't use U2F - not that you should settle for an insecure device.

Re: YubiKey 4C

#83

Remember that closed source security-related products are a complete joke and you should spend your money somewhere else.

Reminder that open source projects are not provably more secure, nor is it easy (or even possible in many cases) to assert the source you see made the binary in question.

Yubikey has been around a long time and has made every effort to be a transparent company with a support for open source. Truth is, that is sometimes hard to do.

I found this article rather interesting, back when it first came out: https://www.yubico.com/2016/05/secure-hardware-vs-open-sourc...

Re: YubiKey 4C

#84
post #25

What are the current alternatives to Yubikey? Preferably looking for something open-source and in no way associated with Google.

Wait – Yubikey is associated with Google? Or did you mean that whatever alternatives people suggest mustn't be associated with Google?

Re: YubiKey 4C

#85
post #10
post #6

Earlier quoted context omitted.

Yes, still closed source.

/me closes tab and gets on with day :) [edit] Interested to know why people find the need to downvote this, I asked a question and got an answer. Please enlighten me so I don't err again.

> /me closes tab and gets on with day :)

Rude dismissive instant messaging language, that doesn't contribute anything to the discussion.

This wouldn't have received any downvotes:

> Ah shame. That's a deal breaker for me. Having open source programming on the device itself is a must-have for me because of [insert reason].

Re: YubiKey 4C

#86
post #68
post #47

I don't think that the people complaining about the price of this key appreciate all that it can do. Most of those people would probably be better off with the cheaper FIDO U2F Security Key. I haven't found anything else that manages RSA Keys, TOTP auth and U2F in a single package. I'm going to buy this because it plugs into my pixel phone and it seems like it'd be more secure and convenient than my current Neo with…

Annoying nerd pedantry: It's only sort of doing TOTP (Yubikeys don't have batteries, so need a software client to provide the clock), and on a slack with almost 300 crypto nerds in it, I don't know any of them that use the Y4 for TOTP (I'm preparing myself to be surprised in a minute when someone there reads this). TOTP is something you do on your phone.

TOTP with Yubikeys is great. You just need the Yubico Authenticator app to access the TOTPs. Works fine on phone using NFC as well as on my (Linux) desktop using USB. New phone? Install YK Authenticator, tap the YK and use your TOTPs.

Re: YubiKey 4C

#87
post #80
post #64

Earlier quoted context omitted.

Some people will tell you to buy two Yubikeys and leave one as a backup. I don't think that's necessary. No matter what, you should generate a backup software key and keep it on offline encrypted storage; if you lose the token, just use the backup key until your replacement arrives. It's even easier for Github and Google Mail. For web services, the right stack is: * Hardware U2F token * Backup software TOTP (Duo or G…

Isn't disabled SMS overkill for most casual thread models? As I understand it SMS would require someone to MITM the telecom network OR snoop the local antenna when you receive it on your phone. Which is a danger if you expect, like, nation-state adversaries. But if I'm, say, protecting my GitHub account against Russian mafia hackers, that still seems perfectly fine?

I can't speak to current day, but in the past it's been very easy to social engineer telecoms. So especially for high value accounts this shouldn't be used.

Re: YubiKey 4C

#88
post #80
post #64

Earlier quoted context omitted.

Some people will tell you to buy two Yubikeys and leave one as a backup. I don't think that's necessary. No matter what, you should generate a backup software key and keep it on offline encrypted storage; if you lose the token, just use the backup key until your replacement arrives. It's even easier for Github and Google Mail. For web services, the right stack is: * Hardware U2F token * Backup software TOTP (Duo or G…

Isn't disabled SMS overkill for most casual thread models? As I understand it SMS would require someone to MITM the telecom network OR snoop the local antenna when you receive it on your phone. Which is a danger if you expect, like, nation-state adversaries. But if I'm, say, protecting my GitHub account against Russian mafia hackers, that still seems perfectly fine?

No, defeating SMS security is not a state-level-adversary task.

Re: YubiKey 4C

#89
I bought a HyperFido but it just doesn't work on Ubuntu...

Was expecting to be able to use it to log in to Google using their 2FA key.. but only works on Windows from what I can see...

Anyone know anything about this?

Post reply on HN