Until these things work well with phones, I can't buy into them. I have a U2F key that I use as a shortcut for accessing things like Google's services. But I am sticking to always using either Google Authenticator or SMS, if it's available, as a primary option. When I am looking at a website in bed on my phone, and my YubiKey is in my laptop downstairs, I can't say I am happy that I can't access my account. I think t…
YubiKey 4C
111–120 of 266 posts
Re: YubiKey 4C
#112Is this Yubikey capable of something similar?
Re: YubiKey 4C
#113Note that this isn't just a U2F key; if you're looking for a token principally to log into web services with, this isn't what you want, and the token that does that costs less than half as much (it's the U2F-only token). You want a Y4 if: * You SSH into sensitive machines. * You log into a VPN that you control and can configure to use the Y4. * You're actually relying on PGP.
Does anyone have a guide on how to store an SSH key on it? I only found PGP key guides (and I have my key on it), but not much for SSH. I also think it doesn't do ECC...
https://github.com/lfit/ssh-gpg-smartcard-config/blob/master...
Re: YubiKey 4C
#114Do they work any better on iPhones? ----- I decided couple of months ago to secure entire family. Bought half dozen Neos, worked out all the kinks on my computer + Android phone first, put everything in LastPass (I know, I know, I know... but you have to consider the target audience ;).... only to discover on "go-live" that my wife's iPhone 6s is bloody useless with the thing. Apparently iPhone doesn't fully grok NFC…
Re: YubiKey 4C
#115Until these things work well with phones, I can't buy into them. I have a U2F key that I use as a shortcut for accessing things like Google's services. But I am sticking to always using either Google Authenticator or SMS, if it's available, as a primary option. When I am looking at a website in bed on my phone, and my YubiKey is in my laptop downstairs, I can't say I am happy that I can't access my account. I think t…
They have a NFC yubikey available, and most new phones work with USB-C (which this one has)
Re: YubiKey 4C
#116Earlier quoted context omitted.
/me closes tab and gets on with day :) [edit] Interested to know why people find the need to downvote this, I asked a question and got an answer. Please enlighten me so I don't err again.
> /me closes tab and gets on with day :) Rude dismissive instant messaging language, that doesn't contribute anything to the discussion. This wouldn't have received any downvotes: > Ah shame. That's a deal breaker for me. Having open source programming on the device itself is a must-have for me because of [insert reason].
Re: YubiKey 4C
#117Earlier quoted context omitted.
/me closes tab and gets on with day :) [edit] Interested to know why people find the need to downvote this, I asked a question and got an answer. Please enlighten me so I don't err again.
> /me closes tab and gets on with day :) Rude dismissive instant messaging language, that doesn't contribute anything to the discussion. This wouldn't have received any downvotes: > Ah shame. That's a deal breaker for me. Having open source programming on the device itself is a must-have for me because of [insert reason].
I'll refrain from inserting IRC commands in future too :)
Re: YubiKey 4C
#118I was just looking around yesterday for a programmatic way to encrypt/decrypt a file with a USB fob. I used an Aladdin fob a while back for a similar project. The encryption was symmetric but the fob kept the key and it couldn't be exported - so it was safe enough for my application. Is this Yubikey capable of something similar?
Re: YubiKey 4C
#119Earlier quoted context omitted.
You obviously didn't read the article. There is no way for you to actually do that. And the secure platforms themselves have NDAs around their specs and software tooling. So yeah, there is a reason they didn't do that. The hardware they're using specifically makes it difficult to do the verification you want to do. Which is directly related to foiling the kind of attacks they want to foil. > If you want to convince y…
I have read the article, several times, thank you very much. Don't take the easy way out by dismissing the opposition as ignorant. >So yeah, there is a reason they didn't do that. The hardware they're using specifically makes it difficult to do the verification you want to do. Which is directly related to foiling the kind of attacks they want to foil. Then they've chosen the wrong hardware. This doesn't make it more…
If the hardware is more resistant to hardware and software attacks, it seems odd to then deem it less secure just because you don't get source code that isn't guaranteed to correspond to a given binary.
> reproducable builds
There's so much literature on how this methodology fails, some of it quite famous. There is no assurance that your device conforms to the build you can reproduce, unless you can arbitrarily inspect the state of the entire device at each step. Being able to do that would defeat the purpose of these devices.
Re: YubiKey 4C
#120Obviously the vast majority of people who use these devices are able-bodied and are able to use them as designed, but if somebody solves this problem there really is a market for it. They are great products, and if it weren't for this one stumbling block I would definitely be using them in my daily life. The inside of my laptop is the only privacy I have, and being able to have complete control over the locking and unlocking of it would be amazing.
It would be great if Apple made it possible to use the accessibility software on the login screen, that way I could tap in my own password but you can't use the accessibility software until you are inside the OS. Grrr.
Anybody got any ideas about how I could solve this, or any direction I could investigate?
(Sorry for mildly hijacking the thread, but thought it was somewhat relevant)