Earlier quoted context omitted.
In my opinion it's not worth the effort (and certainly not $50). It makes marginally +X harder to exploit yet marginally +X inconvenient to use = typical security through obscurity.
You've lost me at "security through obscurity".
YubiKey 4C
261–266 of 266 posts
Re: YubiKey 4C
#262Earlier quoted context omitted.
1. enter company you don't work at and steal laptop at lunch hour 2. walk to cafeteria with laptop that looks like any other. let owner watch unlock it for you. 3. profit! 4. optional, return laptop before lunch is over for full stealth.
Worth noting that the watch alerts that it has been used to unlock the laptop. Doesn't prevent the action, but does prevent "stealth mode unlock"
Most people will just ignore it and call a fluke. Just like everyone does when their servers signatures changes. everyone just save the new key and type their passwords away ;)
Re: YubiKey 4C
#263Earlier quoted context omitted.
Yes. You have to check out the PIV module. It can even be used as a CA. https://developers.yubico.com/PIV/Guides/ There are a number of tools you can install yubico-piv-manager/yubico-piv-tool but check the guides. I had some problems with this, somehow I could not add the key to ssh-agent, but that was related to the ssh-agent, not sure its a general problem. Note, this does only support 2k keys. If you use the GPG…
Thank you, this is the best guide I've seen so far. It's much simpler to install and use. However, like you, I'm having some problems. Adding the key to the ssh-agent asks for a PKCS password and always comes back with "agent refused cooperation". I also can't log in to a host that has that SSH key, but maybe that's because I have too many keys loaded... EDIT: Never mind, it works perfectly, thanks!
How did you solve it?
Re: YubiKey 4C
#264Earlier quoted context omitted.
Thank you, this is the best guide I've seen so far. It's much simpler to install and use. However, like you, I'm having some problems. Adding the key to the ssh-agent asks for a PKCS password and always comes back with "agent refused cooperation". I also can't log in to a host that has that SSH key, but maybe that's because I have too many keys loaded... EDIT: Never mind, it works perfectly, thanks!
This is the issue I had. I can access the key directly from the file but not add it. How did you solve it?
Unfortunately, there's no perfect solution, so I just added an alias "yubissh" to include the library in the command line :(
Re: YubiKey 4C
#265Earlier quoted context omitted.
Actually they can. Features are being added, for example using iphone's nfc chip as a work pass.
cite? first I've heard of it.