Live data from Hacker News

YubiKey 4C

yubico.com

231–240 of 266 posts

Re: YubiKey 4C

#231
post #40
post #22

Until there's a YubiKey 4C nano, I'll wait. Having something of that size sticking out of my computer is not really practical. Not having it inserted defeats the whole point.

I'm kind of wondering what the benefit is over having something like Yubikey at all instead of something that's just software when you just leave it in all the time.

I specifically use it to store my gpg/ssh keys on it. The keys are generated on the device and have never been in any computer's memory. The key answers challenges from an SSH server with the appropriate response. I do not want to insert something dangling off my key every time I do git push.

Re: YubiKey 4C

#232

Earlier quoted context omitted.

I'm reminded of the brief experiences I had w/ Greg Priest Dorman and his physical computing setup, which had him attaching keyboards to his hands, and displays to his glasses. This is a really hacky/bespoke idea, and I apologize if I'm being naive, but I wonder if you might be able to string a Yubikey Nano ( https://www.yubico.com/product/yk4nano/ ) via a USB extension cable to someplace accessible to you around you…

I thought of this when the Yubikey first came out, but apparently it needs to be your finger that makes the connection. I'm not sure if that's still the case, because like you I just assumed I could extend the key somewhere around my chin controller and then use the tip of my nose to activate the key. I believe the tip of your nose is actually fairly unique FYI. But yes, that would be one solution and great minds thi…

I'm pretty sure the nano just needs a poke and then it'll spit out whatever you've configured it to do. I got one and used it for a little while to unlock my computer, by just having it spit out a static password on touch. The issue with this of course is that your password is now visible in clear text just by placing the key in a USB port, opening up a text input, and then touching the key. It was convenient, but very insecure obviously. Maybe it would be useful to you though.

In fact how about this, you can have mine – for free. I never use it anymore, and if there's a chance it'll help you I'm happy to just send it your way. It's just collecting dust at this point anyway.

Re: YubiKey 4C

#233

Earlier quoted context omitted.

Apple decided that users cannot use the NFC chip in it except for Apple Pay (for the foreseeable future). You don't really 'own' an Iphone in that sense.

Actually they can. Features are being added, for example using iphone's nfc chip as a work pass.

cite? first I've heard of it.

Re: YubiKey 4C

#234

Earlier quoted context omitted.

Technically, this could/should have been already solved with voice authentication. Nuance and other companies have been claiming/pushing it for a few years now: http://www.nuance.com/for-business/customer-service-solution... . I'd actually expect Apple to be the first big player to incorporate that, as they've been a leader in accessibility. Maybe somebody should sue them for discrimination to accelerate the process.

Yeah, I've been using voice dictation software since I became quadriplegic over a decade ago and they were talking about it then but it's not materialised yet. I would imagine that it's going to be Apple there's going to be first in this area, but I'm not convinced they're going to do it for accessibility reasons, I think they're going to do it for payment/password reasons. Which if I get the trickle-down benefits fr…

Apple actually did do voice authentication back on Mac OS 9. See http://www.gcsf.com/extras/mwj/mos9special/ (figure ten).

I assume they dropped it because it wasn't actually secure, I remember my brother getting past mine once with only a couple of tries.

Presumably we could do better today, but as far as biometrics go, I'd put my money on Windows Hello's facial recognition over voice showing up again. Apparently they've done a better job of it than the Android handsets a couple years ago managed.

Re: YubiKey 4C

#235
post #200
post #194

Earlier quoted context omitted.

You could buy an Apple Watch and use that to unlock your Mac based on vicinity: https://support.apple.com/en-us/HT206995 Only works on newer MacBook though.

1. enter company you don't work at and steal laptop at lunch hour 2. walk to cafeteria with laptop that looks like any other. let owner watch unlock it for you. 3. profit! 4. optional, return laptop before lunch is over for full stealth.

[deleted]

Re: YubiKey 4C

#236

Earlier quoted context omitted.

On Android, the Google Authenticator app handles U2F via NFC. Sadly not possible on iOS.

For the web, yes, but I don't know any native apps that use it. I still need an app password for gmail, for example.

Huh? All Google native apps use Android's account syncing, which definitely supports using Authenticator for U2F. I'm confident it's also possible to implement it on other apps, although it's a matter of those app developers doing so.

Re: YubiKey 4C

#237
post #194

I REALLY wish it were possible to use one of these devices without using your hands. I'm quadriplegic and would love to use one of these to unlock my computer, bank passwords etc etc. But you have to touch a finger to almost all of them to trigger the OTP, or whichever authentication and they happen to be using. I would absolutely love to be able to lock and unlock my Mac without an able-bodied person helping me, bec…

You could buy an Apple Watch and use that to unlock your Mac based on vicinity: https://support.apple.com/en-us/HT206995 Only works on newer MacBook though.

I had very little luck trying to set this up, and it required me to switch to a different second factor authentication that ended up complicating my life for everything else. Do Not Recommend.

Re: YubiKey 4C

#239
post #219
post #3

Why are Yubikeys so expensive? I have one and use them but the price always gets in the way of having more.

They do lots of stuff. A YubiKey 4 has GPG Smartcard, U2F, PIV (SSH,CA, Windows Remote Login), Static Password, Yubikey OTP, Challenge Response Mode (HMAC) and HOTP. It does a lot of stuff, I am amazed how cheap they are. Pure U2F sticks can be done much cheaper. The Yubikey one only costs 18$, but the U2F standards was designed for cheap devices. You can get U2F sticks for less then 10$ on amazon.

Yup. they're a bargain compared to most solutions

Re: YubiKey 4C

#240

Remember that closed source security-related products are a complete joke and you should spend your money somewhere else.

Well, with that logic, open-source security-related products are a complete joke, too.

- Microprocessor can look at the binary, recognize the patterns ("oh, this is OpenSSH trying to generate a key... lets give them an easily breakable one") and do whatever it wants with it.

Remediation: build your own compilers, build you own processors, from your own schematics, in your own foundry (cost: $billions), built by yourself.

Good luck?

Post reply on HN