Live data from Hacker News

YubiKey 4C

yubico.com

171–180 of 266 posts

Re: YubiKey 4C

#171
post #157

Until these things work well with phones, I can't buy into them. I have a U2F key that I use as a shortcut for accessing things like Google's services. But I am sticking to always using either Google Authenticator or SMS, if it's available, as a primary option. When I am looking at a website in bed on my phone, and my YubiKey is in my laptop downstairs, I can't say I am happy that I can't access my account. I think t…

I think I'm not understanding the problem. I have cloned keys (for backup + two locations), with Yubico Authenticator. Is the problem NFC on iOS or that you don't want to clone your keys?

How do you clone a YubiKey? I thought the whole point of having a hardware token in the first place was that it's _not_ easily copied?

Re: YubiKey 4C

#172

Earlier quoted context omitted.

Why not run an operating system that does let you use accessibility software at the login screen?

My friend, if you could find me an operating system that can do that, and then once inside the OS enable me to use every single function of the operating system like an able-bodied person in the way the Apple's does I'll give you a small prize. I would absolutely love to use free and open source software for both my operating system and everything else, but only Apple provides an experience for people with profound d…

Sounds like you might have tried this already, but GNOME has had a history of working on accessibility, and I think they're quite open to bugs in case something is broken. How well it works in practice, I don't know, though:

https://wiki.gnome.org/Accessibility

Fedora or Debian is probably the easiest way to get a GNOME desktop these days.

Re: YubiKey 4C

#173

Earlier quoted context omitted.

>It renders your point about source code moot though, doesn't it. Security is ultimately the art of trust propagation. I don't see how that follows. If I can audit the source code and confirm that the same code is running on the device, the weak link is reduced to my ability to aduit it (combined with everyone else who's auditing it as well and might publish their findings). >The most famous discourse here is the "un…

> the weak link is reduced to my ability to aduit it (combined with everyone else who's auditing it as well and might publish their findings). And if the hardware itself has microcode that overrides your code? > but this is ridiculous. Do you really think that the Yubikey folks have backdoored my copy of gcc? Actually, I think the first and foremest threat would be, "Could someone insert a yubikey into a malicious de…

>And if the hardware itself has microcode that overrides your code?

Hard to defend against this, but it can be helped by using well understood architectures and letting us confirm that the microcode being run is the same microcode that the upstream CPU vendors are publishing.

>Actually, I think the first and foremest threat would be, "Could someone insert a yubikey into a malicious device that changed its behavior such that it now leaks information and does not provide actual security."

I'm not going to keep entertaining this discussion if you keep disregarding everything I've already said. I've already said I'm only asking for read-only access. In any case, defending against physical compromise is close to impossible anyway.

Re: YubiKey 4C

#174
post #115
post #107

Earlier quoted context omitted.

They have a NFC yubikey available, and most new phones work with USB-C (which this one has)

I can confirm that the NFC support works (yubikey neo with a nexus 5x) - but very few applications and sites support it.

it worked for everything i was using it with. but same problem as the OP mentioned, i dont always have my keys on me so it just became annoying after a while having to the thing first

Re: YubiKey 4C

#175

Earlier quoted context omitted.

> the weak link is reduced to my ability to aduit it (combined with everyone else who's auditing it as well and might publish their findings). And if the hardware itself has microcode that overrides your code? > but this is ridiculous. Do you really think that the Yubikey folks have backdoored my copy of gcc? Actually, I think the first and foremest threat would be, "Could someone insert a yubikey into a malicious de…

>And if the hardware itself has microcode that overrides your code? Hard to defend against this, but it can be helped by using well understood architectures and letting us confirm that the microcode being run is the same microcode that the upstream CPU vendors are publishing. >Actually, I think the first and foremest threat would be, "Could someone insert a yubikey into a malicious device that changed its behavior su…

> if you keep disregarding everything I've already said. I've already said I'm only asking for read-only access.

And I've addressed that.

> In any case, defending against physical compromise is close to impossible anyway.

This is a non-statement. I think your religion is getting in the way of further discussion. Goodbye.

Re: YubiKey 4C

#176
post #157

Earlier quoted context omitted.

I think I'm not understanding the problem. I have cloned keys (for backup + two locations), with Yubico Authenticator. Is the problem NFC on iOS or that you don't want to clone your keys?

How do you clone a YubiKey? I thought the whole point of having a hardware token in the first place was that it's _not_ easily copied?

> How do you clone a YubiKey?

It's a one-time write of a seed at device set-up time. It's not an exact clone, but will give the same response to certain challenges.

https://www.yubico.com/support/knowledge-base/categories/art...

https://www.yubico.com/products/services-software/personaliz...

> I thought the whole point of having a hardware token in the first place was that it's _not_ easily copied?

The process generally requires the person personalizing the key to intend to make two (or more) from the beginning of the process. Otherwise, the secret bits that must be entered into the other device to allow one's 2nd Yubikey to generate the same responses to the same challenges will be lost...

Re: YubiKey 4C

#178
post #147

Earlier quoted context omitted.

Why not run an operating system that does let you use accessibility software at the login screen?

Does Windows 10 let you use accessibility software on the login screen?

Yes. Most new Windows 10 devices such as a Surface Book or Surface Pro have facial recognition built-in. I haven't typed in a password in over a year.

Re: YubiKey 4C

#179
post #172

Earlier quoted context omitted.

My friend, if you could find me an operating system that can do that, and then once inside the OS enable me to use every single function of the operating system like an able-bodied person in the way the Apple's does I'll give you a small prize. I would absolutely love to use free and open source software for both my operating system and everything else, but only Apple provides an experience for people with profound d…

Sounds like you might have tried this already, but GNOME has had a history of working on accessibility, and I think they're quite open to bugs in case something is broken. How well it works in practice, I don't know, though: https://wiki.gnome.org/Accessibility Fedora or Debian is probably the easiest way to get a GNOME desktop these days.

Thanks, I tried persevering with gnome for quite a while because I wanted to use Linux day-to-day. But all of the accessibility stuff at the time was a subset of all of the things that ordinary user could do, that just wasn't enough when I started working and I needed something as full featured as Apple's offering.

I mean I'm obviously going to try and change the state of accessibility and Linux by submitting bug reports and getting involved, but it's a long slow process and in the meantime I need a computer that works.

Re: YubiKey 4C

#180

Remember that closed source security-related products are a complete joke and you should spend your money somewhere else.

You are taking what you personally consider to be a guarantee and applying it to mean what everyone else considers to be a guarantee.

Unless you physically inspect each and every device (since they could easily run multiple lots) your faith is in the fabrication of all of the ICs used in the design. Not to mention that the computer you stick these into suffers from the same problem. On the theoretical side, all of the math which this is based upon is probably taken by most people on a faith basis. There is a lot of faith to go around. It just depends where you draw the line.

Post reply on HN