Live data from Hacker News

YubiKey 4C

yubico.com

201–210 of 266 posts

Re: YubiKey 4C

#201

I REALLY wish it were possible to use one of these devices without using your hands. I'm quadriplegic and would love to use one of these to unlock my computer, bank passwords etc etc. But you have to touch a finger to almost all of them to trigger the OTP, or whichever authentication and they happen to be using. I would absolutely love to be able to lock and unlock my Mac without an able-bodied person helping me, bec…

Yubico has another decive the Nano. It is designed with a switch instead of a button. I am almost sure that you could tie a string around it and then you could maybe pull that somehow, connect it to something mechanical or something.

Mmmhh, why not test this ...

... I have just tried this out. I used the wires from an old headphone and tied it to the trigger. I can Trigger the single click by pulling on the wire. I even managed to trigger the long click, but that was not very practical. I tried pulling it with my mouth, but since you don't need that much force, maybe connect to headphones or something would be enough. My laptop was constantly shifting about, but maybe if you have setup where the computer is fixed, that might be less of a problem.

You can configure the static password on Slot 1 (single click) and you can still use U2F if you like (You can even login with U2F and use Slot 1 for something else as well).

I don't know what your setup is, but that's the idea that jumped to my head. Sorry if it is stupid.

Re: YubiKey 4C

#202

Until these things work well with phones, I can't buy into them. I have a U2F key that I use as a shortcut for accessing things like Google's services. But I am sticking to always using either Google Authenticator or SMS, if it's available, as a primary option. When I am looking at a website in bed on my phone, and my YubiKey is in my laptop downstairs, I can't say I am happy that I can't access my account. I think t…

Whats the point of having two factors at all if you are getting an SMS or using a TOTP token that is stored on the phone itself.

The phone does not force re-entry of this stuff so often that it would bother me.

When I am on my laptop, I absolutely love the Usability. Its much better then SMS or TOTP.

Re: YubiKey 4C

#203

Earlier quoted context omitted.

Apple decided that users cannot use the NFC chip in it except for Apple Pay (for the foreseeable future). You don't really 'own' an Iphone in that sense.

users cannot use the NFC chip in it except for Apple Pay That... boggles my mind :-O Thanks for the info. My wife is unfortunately locked into iPhone due to work standard, but something to keep in mind long-term.

For U2F at least, Bluetooth solutions should be arriving. If Yubico does its on (they have said that they are working on it) they might additionally let you use the OTP stuff.

That said, LassPass says that when Firefox supports U2F, they will also try to support it. So maybe the OTP stuff is not that important.

Dashlane Password Manager already supports it.

Re: YubiKey 4C

#204

Until these things work well with phones, I can't buy into them. I have a U2F key that I use as a shortcut for accessing things like Google's services. But I am sticking to always using either Google Authenticator or SMS, if it's available, as a primary option. When I am looking at a website in bed on my phone, and my YubiKey is in my laptop downstairs, I can't say I am happy that I can't access my account. I think t…

U2F and HOTP (Google Authenticator style 2FA) are not mutually exclusive.

I have both enabled on the sites that support both.

I use U2F when I have the key near me, and use HOTP on my phone otherwise (like you, my phone is typically closer to me than my U2F key).

A common response at this point goes "But then doesn't introducing HOTP remove the security benefits of U2F?" No. One of the main benefits of U2F is that it is phish-proof: the U2F key cryptographically authenticates the server, rather than the user eyeballing the address bar, which is how server "authentication" works with HOTP.

Re: YubiKey 4C

#205
post #200
post #194

Earlier quoted context omitted.

You could buy an Apple Watch and use that to unlock your Mac based on vicinity: https://support.apple.com/en-us/HT206995 Only works on newer MacBook though.

1. enter company you don't work at and steal laptop at lunch hour 2. walk to cafeteria with laptop that looks like any other. let owner watch unlock it for you. 3. profit! 4. optional, return laptop before lunch is over for full stealth.

Worth noting that the watch alerts that it has been used to unlock the laptop. Doesn't prevent the action, but does prevent "stealth mode unlock"

Re: YubiKey 4C

#206
post #200
post #194

Earlier quoted context omitted.

You could buy an Apple Watch and use that to unlock your Mac based on vicinity: https://support.apple.com/en-us/HT206995 Only works on newer MacBook though.

1. enter company you don't work at and steal laptop at lunch hour 2. walk to cafeteria with laptop that looks like any other. let owner watch unlock it for you. 3. profit! 4. optional, return laptop before lunch is over for full stealth.

There are a lot of attacks one can imagine when you have physical access to hardware inside the building. Why not just boot to a thumb drive and install malware?

Re: YubiKey 4C

#207
post #141
post #74

Earlier quoted context omitted.

I'm not saying the 4C doesn't do U2F. It's the same as the 4. I'm saying that if all you want to do is log into web services, you probably don't want the Y4.

more features can even be harmful as in default OTP mode of those devices: https://hackernoon.com/avoid-leaking-your-identity-with-yubi...

Its a good thing to think about, but I don't see it as a huge problem. I had a Yubikey Nano plugged into my laptop almost constantly and I do trigger the OTP sometimes, but using that as an attack vector is pretty hard, specially for all the sticks that are not always plugged in.

Re: YubiKey 4C

#208
post #58

Note that this isn't just a U2F key; if you're looking for a token principally to log into web services with, this isn't what you want, and the token that does that costs less than half as much (it's the U2F-only token). You want a Y4 if: * You SSH into sensitive machines. * You log into a VPN that you control and can configure to use the Y4. * You're actually relying on PGP.

Does anyone have a guide on how to store an SSH key on it? I only found PGP key guides (and I have my key on it), but not much for SSH. I also think it doesn't do ECC...

Yes. You have to check out the PIV module. It can even be used as a CA.

https://developers.yubico.com/PIV/Guides/

There are a number of tools you can install yubico-piv-manager/yubico-piv-tool but check the guides.

I had some problems with this, somehow I could not add the key to ssh-agent, but that was related to the ssh-agent, not sure its a general problem.

Note, this does only support 2k keys. If you use the GPG Smartcard and a Authentication Subkey you can get 4k keys. The advantage of PIV is that you can actually use ssh-agent and you don't have to use gpg-agent. Gpg-agent does not have all the features that ssh-agent does, and for me that was relevant.

I prefer to keep the two separate anyways.

Re: YubiKey 4C

#209

Earlier quoted context omitted.

Thanks for the links, they look really useful and it's only just occurred to me when you pointed it out that when a person such as the key they are completing a circuit. If I could do that in someway that could be unique to me, then that might just be possible to do. I just need to find somebody to do the soldering!. :-)

It depends on the device, but if it's a regular capacitance sensor, what's really needed is just some mildly conductive object touching the sensor - something akin to a human finger. Does not have to be personalized, since this is not a fingerprint sensor. I have an older Yubikey stashed somewhere - if I can unearth it, I'll do some tests. But I suspect it could be something as simple as a wire: on one end touching t…

I had a Nano. I'm like 99% sure all the GP would have to do is tie a wire to the metal tab, and then he could bump the other end of the wire with any part of his body.

Re: YubiKey 4C

#210

I wish you could use these with macOS's CoreStorage to unlock FileVault 2's full disk encryption in combination with a password. I wonder if it'll be possible at any point...

I've done OSX authentication (mainly adding 2FA to the login screen), and Apple doesn't provide any mechanism to interact with unlocking FileVault.

However, with the Yubikey you can type in your password, then have the Yubikey enter your static password. That way you sort of get 2FA for the unlock screen.

Post reply on HN