Live data from Hacker News

YubiKey 4C

yubico.com

161–170 of 266 posts

Re: YubiKey 4C

#161

Earlier quoted context omitted.

>If the hardware is more resistant to hardware and software attacks, it seems odd to then deem it less secure just because you don't get source code that isn't guaranteed to correspond to a given binary. It may be, but there's no guarantee it behaves the way it claims to. There's no guarantee it's not backdoored. There are powerful actors involved in these areas. >There's so much literature on how this methodology fa…

> It may be, but there's no guarantee it behaves the way it claims to. There's no guarantee it's not backdoored. There are powerful actors involved in these areas. It renders your point about source code moot though, doesn't it. Security is ultimately the art of trust propagation. > Care to cite some of this literature? The most famous discourse here is the "untrustworthy compiler problem." Most famous citation is by…

>It renders your point about source code moot though, doesn't it. Security is ultimately the art of trust propagation.

I don't see how that follows. If I can audit the source code and confirm that the same code is running on the device, the weak link is reduced to my ability to aduit it (combined with everyone else who's auditing it as well and might publish their findings).

>The most famous discourse here is the "untrustworthy compiler problem."

I thought this might be what you're talking about, but this is ridiculous. Do you really think that the Yubikey folks have backdoored my copy of gcc? Dude.

Re: YubiKey 4C

#162

Until these things work well with phones, I can't buy into them. I have a U2F key that I use as a shortcut for accessing things like Google's services. But I am sticking to always using either Google Authenticator or SMS, if it's available, as a primary option. When I am looking at a website in bed on my phone, and my YubiKey is in my laptop downstairs, I can't say I am happy that I can't access my account. I think t…

On Android, the Google Authenticator app handles U2F via NFC. Sadly not possible on iOS.

For the web, yes, but I don't know any native apps that use it. I still need an app password for gmail, for example.

Re: YubiKey 4C

#163

I REALLY wish it were possible to use one of these devices without using your hands. I'm quadriplegic and would love to use one of these to unlock my computer, bank passwords etc etc. But you have to touch a finger to almost all of them to trigger the OTP, or whichever authentication and they happen to be using. I would absolutely love to be able to lock and unlock my Mac without an able-bodied person helping me, bec…

Technically, this could/should have been already solved with voice authentication. Nuance and other companies have been claiming/pushing it for a few years now: http://www.nuance.com/for-business/customer-service-solution... . I'd actually expect Apple to be the first big player to incorporate that, as they've been a leader in accessibility. Maybe somebody should sue them for discrimination to accelerate the process.

Yeah, I've been using voice dictation software since I became quadriplegic over a decade ago and they were talking about it then but it's not materialised yet. I would imagine that it's going to be Apple there's going to be first in this area, but I'm not convinced they're going to do it for accessibility reasons, I think they're going to do it for payment/password reasons. Which if I get the trickle-down benefits from then, go Apple!

Re: YubiKey 4C

#164
post #147

Earlier quoted context omitted.

Why not run an operating system that does let you use accessibility software at the login screen?

Does Windows 10 let you use accessibility software on the login screen?

Nope. And in my not so humble opinion and speaking from long and frustrating experience, using Windows accessibility software blows really really hard.

Really. Hard.

Re: YubiKey 4C

#165

I REALLY wish it were possible to use one of these devices without using your hands. I'm quadriplegic and would love to use one of these to unlock my computer, bank passwords etc etc. But you have to touch a finger to almost all of them to trigger the OTP, or whichever authentication and they happen to be using. I would absolutely love to be able to lock and unlock my Mac without an able-bodied person helping me, bec…

It sounds like you would be better served with a Bluetooth proximity-based device like a Gatekeeper.

http://www.gkchain.com/gatekeeper.html

I haven't looked into the OTP functionality of it, since I decided to go with a YubiKey myself, but a friend loves it for hands-free automatic locking and unlocking of his computer as he comes and goes.

Re: YubiKey 4C

#166

Earlier quoted context omitted.

> It may be, but there's no guarantee it behaves the way it claims to. There's no guarantee it's not backdoored. There are powerful actors involved in these areas. It renders your point about source code moot though, doesn't it. Security is ultimately the art of trust propagation. > Care to cite some of this literature? The most famous discourse here is the "untrustworthy compiler problem." Most famous citation is by…

>It renders your point about source code moot though, doesn't it. Security is ultimately the art of trust propagation. I don't see how that follows. If I can audit the source code and confirm that the same code is running on the device, the weak link is reduced to my ability to aduit it (combined with everyone else who's auditing it as well and might publish their findings). >The most famous discourse here is the "un…

> the weak link is reduced to my ability to aduit it (combined with everyone else who's auditing it as well and might publish their findings).

And if the hardware itself has microcode that overrides your code?

> but this is ridiculous. Do you really think that the Yubikey folks have backdoored my copy of gcc?

Actually, I think the first and foremest threat would be, "Could someone insert a yubikey into a malicious device that changed its behavior such that it now leaks information and does not provide actual security."

Because those kinds of attacks actually exist. Ultimately, what you're arguing for is the pleasure and moral superiority of being able to do that audit. Not only does that audit not give you many guarantees, but giving you the ability to do that audit opens you up to much more sinister attacks.

Re: YubiKey 4C

#167
post #22

Until there's a YubiKey 4C nano, I'll wait. Having something of that size sticking out of my computer is not really practical. Not having it inserted defeats the whole point.

This isn't something you should leave plugged in. It's a key after all used for authentication. Keep it on your keychain or in your wallet and plug in as needed.

The security is that it requires physical presence (your finger completing a circuit) to perform authentication. Leaving it plugged in doesn't detract from that.

Re: YubiKey 4C

#168

I REALLY wish it were possible to use one of these devices without using your hands. I'm quadriplegic and would love to use one of these to unlock my computer, bank passwords etc etc. But you have to touch a finger to almost all of them to trigger the OTP, or whichever authentication and they happen to be using. I would absolutely love to be able to lock and unlock my Mac without an able-bodied person helping me, bec…

It sounds like you would be better served with a Bluetooth proximity-based device like a Gatekeeper. http://www.gkchain.com/gatekeeper.html I haven't looked into the OTP functionality of it, since I decided to go with a YubiKey myself, but a friend loves it for hands-free automatic locking and unlocking of his computer as he comes and goes.

That looks great, thank you for the link. I would love to try one of those devices, I don't have great memories of this kind of unlocking though.

I can't remember the exact name of the product, but I installed it with good faith and it completely locked up my Mac so badly I had to reformat the computer.

So colour me a little reticent to try this, although if the gatekeeper guys are reading this I'll be happy to beta test one for you. You know, purely for accessibility reasons. :-)

Re: YubiKey 4C

#169

Do they work any better on iPhones? ----- I decided couple of months ago to secure entire family. Bought half dozen Neos, worked out all the kinks on my computer + Android phone first, put everything in LastPass (I know, I know, I know... but you have to consider the target audience ;).... only to discover on "go-live" that my wife's iPhone 6s is bloody useless with the thing. Apparently iPhone doesn't fully grok NFC…

The yubikey is the something you have. You can use the iphone in place of that.

Re: YubiKey 4C

#170
post #73
post #40

Earlier quoted context omitted.

I'm kind of wondering what the benefit is over having something like Yubikey at all instead of something that's just software when you just leave it in all the time.

Your computer can in theory get owned up without you losing your SSH or VPN keys, even if your keystrokes are logged.

Get owned = SSH is hikacked = I don't need your keys and can run any commands on your behalf.

This thing might protect from keyloggers but useless against proper malware that just waits for you to authenticate.

Post reply on HN