Live data from Hacker News

Yubico and Microsoft Introduce Passwordless Login

yubico.com

61–70 of 218 posts

Re: Yubico and Microsoft Introduce Passwordless Login

#61
post #57

Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…

Every place that I use my key gives you a set of one-time-use recovery codes. To log into your account, you can use either the key or a code. (You still need your password.) Codes can be regenerated at any time. To revoke a key, you simply remove it from your account.

Re: Yubico and Microsoft Introduce Passwordless Login

#62
Would be interesting if this would become popular one downside I see to this is that if law enforcement get their hands on your token they can unlock the device. Also as the token can be regarded as a key rather than a password a court would be able to legally compel you to surrender it without invoking much debate regarding laws against self incrimination (e.g. the fifth).

Re: Yubico and Microsoft Introduce Passwordless Login

#63
post #50
post #37

Earlier quoted context omitted.

So in this case, arent the two factors a) physical possession of desktop/laptop and b) the Yubikey ? How likely is it you'll lose both if you keep your keyring with you?

Not sure reading the article why would I need the computer. The way I read it, you enter the key to any computer and it logs in to the account of the key owner. Am I wrong?

FTA: "Organizations will soon have the option to enable employees and customers to sign in to an Azure AD joined device with no password, by simply using a Security Key to get single sign-on to all Azure AD based applications and services."

Emphasis added. Device needs to be paired with Company's AD first.

I also imagine that there are options for making e.g. the device unlock only require yubikey, but login to SSO require 2nd factor.

Re: Yubico and Microsoft Introduce Passwordless Login

#64
post #9

Two things - is there really need for them to be this large? They also look vulnerable? Maybe its just the look, but the blue one looks like it won't survive proper stress test... And second thing - is exposing connector safe against mechanical damage? Will it withstand constantly being scratched by keys?

What kind of stress test do you have in mind? I've had a yubikey 4 for almost two years on my keyring that I use daily and despite not taking very good care of it it still works fine. It's been wet, it's been scratched, it's supported the weight of my keys while hanging from a USB port, it's been plugged and unplugged thousands of times...

They're pretty sturdy. Of course if you take some pliers to them I have no doubt that you'll be able to break them in half but for normal use you won't have a problem IMO. The size doesn't bother me either, it's like a very flat USB key.

I also have a nitrokey that's a bit shorter and bulkier and it comes with a cap which might be better to protect the connector, but on the other hand I'm sure I'd lose it sooner or later. A retractable port or something similar would probably be a better idea. Also the nitrokey is significantly slower which is the main reason I only have it as a backup for my yubikey currently.

Re: Yubico and Microsoft Introduce Passwordless Login

#66
post #61
post #57

Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…

Every place that I use my key gives you a set of one-time-use recovery codes. To log into your account, you can use either the key or a code. (You still need your password.) Codes can be regenerated at any time. To revoke a key, you simply remove it from your account.

You have to make sure the attacker cannot revoke your key first. If the backup code is unrevokable, then it is indeed a nice solution, albeit a high-friction one if you are doing safe backups for each new account.

Re: Yubico and Microsoft Introduce Passwordless Login

#67
post #57

Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…

They should not do this, as this would make Yubico responsible for potential fraud attempts. Existing sites should do the same way they do already.

Re: Yubico and Microsoft Introduce Passwordless Login

#68
post #57

Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…

It sounds like this is targeted at machines that are attached to Active Directory, in which case the fallback is the same as before (you call a help desk/sysadmin, and they "reset your password" aka verify your identity and give you a new security key).

Re: Yubico and Microsoft Introduce Passwordless Login

#69
post #9

Two things - is there really need for them to be this large? They also look vulnerable? Maybe its just the look, but the blue one looks like it won't survive proper stress test... And second thing - is exposing connector safe against mechanical damage? Will it withstand constantly being scratched by keys?

They're incredibly sturdy. I don't know what a proper stress test is, but i hung my keys from my usb socket with it, countless times, it's been on my keyring for years, bent and scratched every which way.

Re: Yubico and Microsoft Introduce Passwordless Login

#70
post #60
post #57

Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…

Neither of those problems (lost key, compromised key) are anything new. Why wouldn't sites just handle them the same way they currently handle revoking/resetting passwords?

Because the current way sucks.

99% of the websites (I have accounts on) rely on my email for recovery and revocation. But my inbox is not an impenetrable fortress, it's a communication channel; every device I own has access to it, and could be used as a backdoor to my entire digital life.

Then there's the risk of the third-party (Google banning me, being hacked, subpoena'd, etc), the privacy factor (see the Ashley Madison leaks), the often custom code implemented by each website...

Post reply on HN