Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…
Yubico and Microsoft Introduce Passwordless Login
61–70 of 218 posts
Re: Yubico and Microsoft Introduce Passwordless Login
#62Re: Yubico and Microsoft Introduce Passwordless Login
#63Earlier quoted context omitted.
So in this case, arent the two factors a) physical possession of desktop/laptop and b) the Yubikey ? How likely is it you'll lose both if you keep your keyring with you?
Not sure reading the article why would I need the computer. The way I read it, you enter the key to any computer and it logs in to the account of the key owner. Am I wrong?
Emphasis added. Device needs to be paired with Company's AD first.
I also imagine that there are options for making e.g. the device unlock only require yubikey, but login to SSO require 2nd factor.
Re: Yubico and Microsoft Introduce Passwordless Login
#64Two things - is there really need for them to be this large? They also look vulnerable? Maybe its just the look, but the blue one looks like it won't survive proper stress test... And second thing - is exposing connector safe against mechanical damage? Will it withstand constantly being scratched by keys?
They're pretty sturdy. Of course if you take some pliers to them I have no doubt that you'll be able to break them in half but for normal use you won't have a problem IMO. The size doesn't bother me either, it's like a very flat USB key.
I also have a nitrokey that's a bit shorter and bulkier and it comes with a cap which might be better to protect the connector, but on the other hand I'm sure I'd lose it sooner or later. A retractable port or something similar would probably be a better idea. Also the nitrokey is significantly slower which is the main reason I only have it as a backup for my yubikey currently.
Re: Yubico and Microsoft Introduce Passwordless Login
#65Can someone explain why CTAP was created? What exactly was wrong / not enough about the original U2F protocol?
Re: Yubico and Microsoft Introduce Passwordless Login
#66Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…
Every place that I use my key gives you a set of one-time-use recovery codes. To log into your account, you can use either the key or a code. (You still need your password.) Codes can be regenerated at any time. To revoke a key, you simply remove it from your account.
Re: Yubico and Microsoft Introduce Passwordless Login
#67Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…
Re: Yubico and Microsoft Introduce Passwordless Login
#68Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…
Re: Yubico and Microsoft Introduce Passwordless Login
#69Two things - is there really need for them to be this large? They also look vulnerable? Maybe its just the look, but the blue one looks like it won't survive proper stress test... And second thing - is exposing connector safe against mechanical damage? Will it withstand constantly being scratched by keys?
Re: Yubico and Microsoft Introduce Passwordless Login
#70Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…
Neither of those problems (lost key, compromised key) are anything new. Why wouldn't sites just handle them the same way they currently handle revoking/resetting passwords?
99% of the websites (I have accounts on) rely on my email for recovery and revocation. But my inbox is not an impenetrable fortress, it's a communication channel; every device I own has access to it, and could be used as a backdoor to my entire digital life.
Then there's the risk of the third-party (Google banning me, being hacked, subpoena'd, etc), the privacy factor (see the Ashley Madison leaks), the often custom code implemented by each website...