Okay, so I have two Yubico U2F keys and two other U2F keys so far. I don't think I'll buy a fifth and sixth anytime soon. But hopefully U2F will actually work in non-Chrome browsers in the near future.
It already works in Firefox (behind a flag), but sadly some websites explicitly target Chrome...
Yubico and Microsoft Introduce Passwordless Login
41–50 of 218 posts
Re: Yubico and Microsoft Introduce Passwordless Login
#42Two things - is there really need for them to be this large? They also look vulnerable? Maybe its just the look, but the blue one looks like it won't survive proper stress test... And second thing - is exposing connector safe against mechanical damage? Will it withstand constantly being scratched by keys?
There is the "nano" version available which is a lot smaller than the one advertised. The ones that I own have held up just fine for the past year on my keychain. https://www.yubico.com/product/yubikey-4-series/#yubikey-4-n...
Re: Yubico and Microsoft Introduce Passwordless Login
#43Okay, so I have two Yubico U2F keys and two other U2F keys so far. I don't think I'll buy a fifth and sixth anytime soon. But hopefully U2F will actually work in non-Chrome browsers in the near future.
It already works in Firefox (behind a flag), but sadly some websites explicitly target Chrome...
Re: Yubico and Microsoft Introduce Passwordless Login
#44Earlier quoted context omitted.
There is the "nano" version available which is a lot smaller than the one advertised. The ones that I own have held up just fine for the past year on my keychain. https://www.yubico.com/product/yubikey-4-series/#yubikey-4-n...
This size is much better, but I assume it lacks the "touch" protection against remote attacks, like the other ones? I still wonder about the exposed connector - what its durability. After all, I would like for such a tool to serve me for years fault-free.
Re: Yubico and Microsoft Introduce Passwordless Login
#45Okay, so I have two Yubico U2F keys and two other U2F keys so far. I don't think I'll buy a fifth and sixth anytime soon. But hopefully U2F will actually work in non-Chrome browsers in the near future.
I would guess you're referring to being able to log in to gmail (or anything in G Suite) with U2F from Firefox.
U2F is already available in the most recent version. See "security.webauth.*" keys in about:config. It just won't work with Google, at least not yet. Google's implementation predates webauth by a pretty fair margin, and from what I have learned, is different in small but important ways from the standard.
So we have a situation that drips irony: we have a U2F standard, usable via a standard authentication mechanism - and incompatible with the very web property that drove the concerted push for the technology's adoption.
Re: Yubico and Microsoft Introduce Passwordless Login
#46Okay, so I have two Yubico U2F keys and two other U2F keys so far. I don't think I'll buy a fifth and sixth anytime soon. But hopefully U2F will actually work in non-Chrome browsers in the near future.
> But hopefully U2F will actually work in non-Chrome browsers in the near future. I would guess you're referring to being able to log in to gmail (or anything in G Suite) with U2F from Firefox. U2F is already available in the most recent version. See "security.webauth.*" keys in about:config. It just won't work with Google, at least not yet. Google's implementation predates webauth by a pretty fair margin, and from w…
Re: Yubico and Microsoft Introduce Passwordless Login
#47Correct me if I am wrong, but passwordless login is a single-factor authentication and less secure than MFA. Depending on whenever hardware key is more or less secure than the password, the mass adoption of this could make things LESS secure.
I would expect things to be more secure in many cases. People are pretty good at keeping physical items somewhat safe and notice when they’re gone. Yubikeys cannot easily be cloned. The password cannot be attacked remotely. 2FA is certainly safer, though.
In this context, it would be reasonable to have the Yubikey require a PIN entry from the computer. You could use the same PIN for all sites because it stays local; the relying party never handles it, only the Yubikey.
Re: Yubico and Microsoft Introduce Passwordless Login
#48Earlier quoted context omitted.
I doubt that. Friends or family can't read your mind, but they can steal your physical key. People putting pins on their phones or password on their laptop are not afraid of being pirated. This is a vague, abstract threat to them. Becoming part of a botnet is really not important to them, and they getting their credit card stolen from the web is really not credible enough for non tech saavy user. What they are afraid…
Anyone in the world could crack your password. (Well, any of 2.5 billion people with an internet connection.) Requiring a physical key instead cuts the attack surface down quite a bit. If you can secure your car and house keys, you can secure this.
Re: Yubico and Microsoft Introduce Passwordless Login
#49Earlier quoted context omitted.
That is confirmed in the "How does this work?" section. Your concern is addressed in the "Why is this important?" section. The key is definitely more secure against cracking than a password. It is more vulnerable to being physically stolen, but for most people, that is a lower risk.
I doubt that. Friends or family can't read your mind, but they can steal your physical key. People putting pins on their phones or password on their laptop are not afraid of being pirated. This is a vague, abstract threat to them. Becoming part of a botnet is really not important to them, and they getting their credit card stolen from the web is really not credible enough for non tech saavy user. What they are afraid…
Your example of people leaving the key with the laptop is a good example of one of the potential flaws, but just like if your credit card gets lost or stolen, you report it and it becomes unusable.
I agree that there is room for 2FA, but this is also surely preferable to the current system.
Re: Yubico and Microsoft Introduce Passwordless Login
#50Earlier quoted context omitted.
Except that passwords at least protect you if your hardware key is stolen. Using just a hardware key seems similarly risky to just using a password.
So in this case, arent the two factors a) physical possession of desktop/laptop and b) the Yubikey ? How likely is it you'll lose both if you keep your keyring with you?