Live data from Hacker News

Ask HN: Alternatives to Yubikey?

news.ycombinator.com

71–80 of 91 posts

Re: Ask HN: Alternatives to Yubikey?

#71
post #45

SecurID has been the gold standard for more than a decade. Not to dismiss YubiKey but companies that can afford 2 factor and take security seriously already have SecurID for a long time.

SecurID is just an expensive TOTP implementation (although a very established one, as you noted) That "gold standard" required reissuing 40 millions of devices in 2011 due to a single server breach. Lockheed-Martin was apparently really, really happy about it, too. If that's your desired level of security, just use any TOTP authenticator app on your smartphone.

Smartphones are insecure unless you can control all your users have new Apple phones.

The problem with many affordable TOTP tokens is clock drift. Are RSA's tokens better with that?

Re: Ask HN: Alternatives to Yubikey?

#72
post #23

Earlier quoted context omitted.

Does not ship to the Netherlands... Meh!

They have an international version that does not ship with encryption of the data stored on the device, to deal with the various laws around encryption in other countries. However, there's no hardware difference, and since it's all open-source, there's nothing stopping you from loading the "US" firmware on the "International" version. More info at their site: https://crp.to/

I think for international customers it's better to buy a working product with international support like yubikey rather than a crippled product like this.

Re: Ask HN: Alternatives to Yubikey?

#73
post #69
post #49

Earlier quoted context omitted.

Does it need an update?

I'd love to be able to select the background color of entries and edit the text at the top of the entry, rather than just the bottom.

Try authy or freeotp or any of the other available on f-droid

Re: Ask HN: Alternatives to Yubikey?

#74
I've had good experiences with Yubikeys thus far. I still have two of the Symantec VIP tokens from years ago that I've never had issues with. I recently bought a Neo to test out NFC (NFC support on the HTC 10 seems deplorable for smart card reading btw). I also purchased a few 4c tokens and so far they've worked great although I haven't been using them for very long.

The gotchas I've encountered while using them on OSX:

  - The pins for PIV and OpenPGP are separate as these are separate modules on the card.
  - You can't use the PIV or NEO GUI managers and gpg at the same time. You might have to unplug and plug the token
    back in when switching back and forth between GUI/cmdline Yubico tools and gpg.
  - Forgetting to change my environment to use gpg-agent instead of ssh-agent.
  - Typing in my local password instead of the PIV pin when logging into OSX while I have a token with PIV enabled
    plugged in.
The "setup" instructions that are referenced in the packaging and on parts of the site are for basic use of OTP. Real documentation is here: https://www.yubico.com/support/knowledge-base/categories/gui...

For people asking about backing up material on OpenPGP modules: these are write only. Generate your material locally with gpg instead of generating them on the smart card itself and use the keytocard command to copy the keys to the card. You can backup your keyring prior to moving keys and restore it before copying keys to each card or ctrl c out of gpg without saving the keyring references for the material that was moved to the smart card.

I used bits and pieces from a few guides to get the setup I wanted as this was my first experience with smart cards and advanced use of pgp:

https://www.esev.com/blog/post/2015-01-pgp-ssh-key-on-yubike...

https://rnorth.org/gpg-and-ssh-with-yubikey-for-mac

http://suva.sh/posts/gpg-ssh-smartcard-yubikey-keybase/

https://www.jfry.me/articles/2015/gpg-smartcard/

https://spin.atomicobject.com/2013/11/24/secure-gpg-keys-gui...

https://alexcabal.com/creating-the-perfect-gpg-keypair/

Overview of my process (on an air gapped machine):

  - Configure gpg.conf.
  - Generate master, subkey, and revocation material on an encrypted USB drive for offline backup of materia
    along with revocation certificates.
  - Backup original .gnupg directory to another folder on the encrypted USB drive. 
  - Copy .gnupg directory to second encrypted USB drive for offsite backup.
  - For each smart card I wanted the same material on:
  -- Change default user and admin pins.
  -- keytocard subkeys for (S)ign, (E)ncrypt, (A)uthenticate (without saving keyring).
  -- Require local touch for all material ( Yubico specific: https://developers.yubico.com/PGP/Card_edit.html ).
  -- move on to next card.
  -- save keyring after running keytocard on the last card so the subkey material no longer exists in the local keyring, only
     references to it (this might not be necessary, I need to test).
  - Generate a copy of the keyring without master key to use on daily machine(s). Might also only need to have the master 
    material minus the key in the keyring as noted above. I haven't tested how 
  - Copy new keyring to another USB drive for transferring to daily machine(s).
  - Configure gpg-agent.conf and gpg.conf on daily machine.

Resetting the applet if you messed up or want to start fresh:

https://developers.yubico.com/ykneo-openpgp/ResetApplet.html

https://www.yubico.com/support/knowledge-base/categories/art...

Re: Ask HN: Alternatives to Yubikey?

#75

I've had good experiences with Yubikeys thus far. I still have two of the Symantec VIP tokens from years ago that I've never had issues with. I recently bought a Neo to test out NFC (NFC support on the HTC 10 seems deplorable for smart card reading btw). I also purchased a few 4c tokens and so far they've worked great although I haven't been using them for very long. The gotchas I've encountered while using them on O…

[deleted]

Re: Ask HN: Alternatives to Yubikey?

#76

Sounds like an opportunity for someone to make consulting money. I have found their docs lacking, but never tried support. Once I muddled through and figured out what I needed, I have been very happy. That said, I have looked for alternatives and found none. I am most disappointed in the mediocre coverage of their RDP drivers. I need to use all the features over RDP. Some work and some don't.

Perhaps?

* Do not allow smart card redirection Group Policy object

Re: Ask HN: Alternatives to Yubikey?

#77
post #42

https://sc4.us/hsm It's fully open-source, but the only standard application currently supported is U2F. Disclosure: this is my product.

FYI your website is blocked by my work proxy:-

Access Denied (content_filter_denied)

Your request was denied because of its content categorization: "Placeholders"

Re: Ask HN: Alternatives to Yubikey?

#78
post #55

I'm annoyed that Lastpass still doesn't support U2F, and I don't really understand the delay at this point.

Their official response is "because not all browsers support it".

It could be a valid business decision (I.e. uneven browser support will confuse our users and increase costs) but I think they are just using that as a delay tactic.

Re: Ask HN: Alternatives to Yubikey?

#79
There's also this thing https://www.protectimus.com/protectimus-slim-mini A little different because it does not plug in, but very convenient. It seems like the usb key solutions are likely to get left plugged into the port, and so get stolen along with the laptop. The protectimus idea is to keep the key on you at all times.

Re: Ask HN: Alternatives to Yubikey?

#80
There's also this thing https://www.protectimus.com/protectimus-slim-mini A little different because it does not plug in, but very convenient. It seems like the usb key solutions are likely to get left plugged into the port, and so get stolen along with the laptop. The protectimus idea is to keep the key on you at all times.
Post reply on HN