Live data from Hacker News

YubiKey 4C

yubico.com

141–150 of 266 posts

Re: YubiKey 4C

#141
post #74

Earlier quoted context omitted.

But it's identical functionality to a Yubikey 4, just with type-C connector, and the product page as well as myself personally can verify that Yubikey 4 supports U2F

I'm not saying the 4C doesn't do U2F. It's the same as the 4. I'm saying that if all you want to do is log into web services, you probably don't want the Y4.

more features can even be harmful as in default OTP mode of those devices: https://hackernoon.com/avoid-leaking-your-identity-with-yubi...

Re: YubiKey 4C

#142
post #131
post #64

Earlier quoted context omitted.

Some people will tell you to buy two Yubikeys and leave one as a backup. I don't think that's necessary. No matter what, you should generate a backup software key and keep it on offline encrypted storage; if you lose the token, just use the backup key until your replacement arrives. It's even easier for Github and Google Mail. For web services, the right stack is: * Hardware U2F token * Backup software TOTP (Duo or G…

Can you disable SMS on google? I've tried and have been unsuccessful. Phone is required to enable 2FA. Once that is enabled, I can add yubikeys. After adding yubikeys, I am unable to remove phone as a 2FA alternative.

It's possible to disable SMS-based 2FA. Perhaps you need another backup option before you're allowed to remove the SMS option. In my case, I was able to do it with two U2F keys, TOTP and backup codes enabled.

You might need to remove it as an account recovery number as well. Those can effectively downgrade your login to one factor.

Re: YubiKey 4C

#143

Earlier quoted context omitted.

Just use a TOTP app, at the moment. Note that because there are no U2F alternatives means that you shouldn't use U2F - not that you should settle for an insecure device.

There are U2F alternatives, several of which are mentioned in this thread. Also, U2F is immune to phishing while TOTP isn't. Your advice is actively harmful.

I believe I'm speaking to an audience that is generally pretty good at not being phished.

Re: YubiKey 4C

#144

I REALLY wish it were possible to use one of these devices without using your hands. I'm quadriplegic and would love to use one of these to unlock my computer, bank passwords etc etc. But you have to touch a finger to almost all of them to trigger the OTP, or whichever authentication and they happen to be using. I would absolutely love to be able to lock and unlock my Mac without an able-bodied person helping me, bec…

[deleted]

Re: YubiKey 4C

#145

Do any of these RSA alternatives have an LCD display showing the id? Our work computers are locked down and USB is not an option.

You can have it behave like a keyboard and simply 'type' the characters of the one time password in. I don't know how locked down your systems but usually keyboards are allowed.

Re: YubiKey 4C

#146

I REALLY wish it were possible to use one of these devices without using your hands. I'm quadriplegic and would love to use one of these to unlock my computer, bank passwords etc etc. But you have to touch a finger to almost all of them to trigger the OTP, or whichever authentication and they happen to be using. I would absolutely love to be able to lock and unlock my Mac without an able-bodied person helping me, bec…

IIRC, the main reason that accessibility software doesn't have access to login screens is because malicious software has historically used accessibility APIs to steal passwords (e.g. by eavesdropping on a login screen, or by presenting a fake one and then using the accessibility APIs to pass through the password to the real one).

Re: YubiKey 4C

#147

I REALLY wish it were possible to use one of these devices without using your hands. I'm quadriplegic and would love to use one of these to unlock my computer, bank passwords etc etc. But you have to touch a finger to almost all of them to trigger the OTP, or whichever authentication and they happen to be using. I would absolutely love to be able to lock and unlock my Mac without an able-bodied person helping me, bec…

Why not run an operating system that does let you use accessibility software at the login screen?

Does Windows 10 let you use accessibility software on the login screen?

Re: YubiKey 4C

#148

I REALLY wish it were possible to use one of these devices without using your hands. I'm quadriplegic and would love to use one of these to unlock my computer, bank passwords etc etc. But you have to touch a finger to almost all of them to trigger the OTP, or whichever authentication and they happen to be using. I would absolutely love to be able to lock and unlock my Mac without an able-bodied person helping me, bec…

Why not run an operating system that does let you use accessibility software at the login screen?

[deleted]

Re: YubiKey 4C

#149

I REALLY wish it were possible to use one of these devices without using your hands. I'm quadriplegic and would love to use one of these to unlock my computer, bank passwords etc etc. But you have to touch a finger to almost all of them to trigger the OTP, or whichever authentication and they happen to be using. I would absolutely love to be able to lock and unlock my Mac without an able-bodied person helping me, bec…

I'm reminded of the brief experiences I had w/ Greg Priest Dorman and his physical computing setup, which had him attaching keyboards to his hands, and displays to his glasses.

This is a really hacky/bespoke idea, and I apologize if I'm being naive, but I wonder if you might be able to string a Yubikey Nano (https://www.yubico.com/product/yk4nano/) via a USB extension cable to someplace accessible to you around your head? Someplace you could trigger it with head motion?

You'd still have to figure out integrating the Nano with your login screen, your password manager, etc, but this seems like it might maybe be a viable first step.

Re: YubiKey 4C

#150

Earlier quoted context omitted.

There are U2F alternatives, several of which are mentioned in this thread. Also, U2F is immune to phishing while TOTP isn't. Your advice is actively harmful.

I believe I'm speaking to an audience that is generally pretty good at not being phished.

The available data suggests there are no groups of people who are good at not being phished.

The audience here is unlikely to send a check to the Nigerian prince looking to smuggle his money to America, but if you're arguing that we shouldn't trust yubikeys against APT backdoors, we're talking about a much higher quality of phishing.

I'll take my odds with yubikeys firmware rather than try to vet every site I enter a TOTP code into

Post reply on HN