Earlier quoted context omitted.
I use my yubikey and I love it. I have it set up to do GPG, SSH, TOTP, and U2F and it works great. It is worlds better then any other Smart Card or second factor out there, and U2F is literally just plug it in and tap it.
Is there any sort of backup in case it gets destroyed or lost? Can you clone it?
Ask HN: Alternatives to Yubikey?
61–70 of 91 posts
Re: Ask HN: Alternatives to Yubikey?
#62Earlier quoted context omitted.
Is there any sort of backup in case it gets destroyed or lost? Can you clone it?
The entire security model depends on the devices being uncloneable.
Re: Ask HN: Alternatives to Yubikey?
#63Earlier quoted context omitted.
The entire security model depends on the devices being uncloneable.
But my security model does not allow putting myself in a position where I am stranded without my second factor (or doing huge amounts of work re-registering everything).
It is for the same reason that services like Google Mail won't let you set up a U2F token without a backup factor.
Re: Ask HN: Alternatives to Yubikey?
#64Re: Ask HN: Alternatives to Yubikey?
#65I recommend the OnlyKey: https://www.amazon.com/OnlyKey-Color-Password-Manager-Obsole... The device uses strong encryption (where legal), and goes beyond U2F to include password management, certificate storage, OTP/Google Auth, and plausible deniability. The hardware is teensy-based, and the firmware is open source. The devs have released fairly regular updates, and even encourage hacking on it to meet custom needs.
Re: Ask HN: Alternatives to Yubikey?
#66Re: Ask HN: Alternatives to Yubikey?
#67SecurID has been the gold standard for more than a decade. Not to dismiss YubiKey but companies that can afford 2 factor and take security seriously already have SecurID for a long time.
SecurID is just an expensive TOTP implementation (although a very established one, as you noted) That "gold standard" required reissuing 40 millions of devices in 2011 due to a single server breach. Lockheed-Martin was apparently really, really happy about it, too. If that's your desired level of security, just use any TOTP authenticator app on your smartphone.
A lot of mails going to the post office. That's one of the good thing about this hardware tokens, you can decommission and replace them easily.
What's expensive it to redo all your applications and systems to have 2 factor authentication.
Re: Ask HN: Alternatives to Yubikey?
#68The DIY open source alternative: https://u2fzero.com/
Is...that...safe? I'm all for the a DIY solution, but considering how much of a pickle I'd be in if all of my 2FA tokens were inaccessible, wouldn't the average person want some kind of case or shielding around the exposed board? Give me an enclosure like Samsung's metal flash drives[0], and then I'd be sold. [0] https://www.amazon.com/Samsung-METAL-Flash-MUF-32BA-AM/dp/B0...