Live data from Hacker News

Yubico and Microsoft Introduce Passwordless Login

yubico.com

71–80 of 218 posts

Re: Yubico and Microsoft Introduce Passwordless Login

#71

Earlier quoted context omitted.

It depends what your threat model looks like. For example if you have good physical security and limit passwordless login to physically secure machines via AD computer groups, this may protect you from remote attackers. If however organizations allow the use of this over the internet from "any" endpoint then this completely replaces a password 1:1 and theft/loss of the Yubikey could be a major problem. This could als…

Unless you're asserting that the hardware token is just as crackable as a password, it's not a 1:1 replacement. The problem with passwords is that you have 10,000 users and more than one of them has a bad password. The problem with hardware tokens is that I've stolen your token. So passwords are vulnerable to bots, while the hardware token requires a human to find/steal something and connect it with a specific accoun…

> Unless you're asserting that the hardware token is just as crackable as a password

That's completely outside the scope of what I was describing. You've taken my words out of context.

Re: Yubico and Microsoft Introduce Passwordless Login

#72
post #57

Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…

> I still use Google Authenticator myself, but I dread the day I lose my phone.

I use KeePassXC, and always add the Google auth code to both my phone and KeePassXC, and I back up my password DB (got burned big time there once....).

But yeah, your point is valid. As a tech savvy guy who thinks about this stuff, it's a pain but works. But for most people manually managing and backing up multitudes of keys, passwords, and login data is just so ridiculous a thing to ask that I can't believe it's 2018 and we haven't solved this yet. There must be a better way!

Re: Yubico and Microsoft Introduce Passwordless Login

#73
No USB-C version and no way to upgrade my other 4+ YubiKeys I've got for more than $50 each! I think YubiKey has been abusing its monopoly recently! They've been working on this for quite some time and clearly new they're not going to make their old premium keys support it so that people can waste time and money to upgrade! Is there an alternative more conscious company - I'd pay even $200 for the piece of mind that I won't have to change this key 1-2 times per year!

P.S. Obviously, no. Neither Nitrokey [0] supports it, nor it's a sturdy one!

[0]: https://www.nitrokey.com/

Re: Yubico and Microsoft Introduce Passwordless Login

#74
post #61
post #57

Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…

Every place that I use my key gives you a set of one-time-use recovery codes. To log into your account, you can use either the key or a code. (You still need your password.) Codes can be regenerated at any time. To revoke a key, you simply remove it from your account.

Can you give a list of all these places?

Gandi doesn't even have a non-human method of recovery.

Re: Yubico and Microsoft Introduce Passwordless Login

#75
post #70
post #60

Earlier quoted context omitted.

Neither of those problems (lost key, compromised key) are anything new. Why wouldn't sites just handle them the same way they currently handle revoking/resetting passwords?

Because the current way sucks. 99% of the websites (I have accounts on) rely on my email for recovery and revocation. But my inbox is not an impenetrable fortress, it's a communication channel; every device I own has access to it, and could be used as a backdoor to my entire digital life. Then there's the risk of the third-party (Google banning me, being hacked, subpoena'd, etc), the privacy factor (see the Ashley Ma…

> every device I own is has access to it

and this sucks. Why can't I use my google account with my tablet without it automatically getting access to gmail sync?

Re: Yubico and Microsoft Introduce Passwordless Login

#76
post #57

Did they improve the stories for recovery ("I lost my device") and revocation ("my device has been stolen")? As far as I knew you had to buy 2 devices to have a chance of recovery, and Fido 1 explicitly said "revocation is something that needs to be resolved by each website that authenticates users", which is just asking for trouble. I would love to have a hardware (or even phone-based) alternative to passwords, with…

Re Google Authenticator, as an alternative have you tried Authy? It offers a far better UX, and if you lose your phone you can easily get everything back without doing a backup/restore before hand. Plus you can run it on as many devices as you require, including desktops.

Re: Yubico and Microsoft Introduce Passwordless Login

#77
post #73

No USB-C version and no way to upgrade my other 4+ YubiKeys I've got for more than $50 each! I think YubiKey has been abusing its monopoly recently! They've been working on this for quite some time and clearly new they're not going to make their old premium keys support it so that people can waste time and money to upgrade! Is there an alternative more conscious company - I'd pay even $200 for the piece of mind that…

I will point out, NitroKey also doesn't have a USB-C version.

Re: Yubico and Microsoft Introduce Passwordless Login

#78
post #70
post #60

Earlier quoted context omitted.

Neither of those problems (lost key, compromised key) are anything new. Why wouldn't sites just handle them the same way they currently handle revoking/resetting passwords?

Because the current way sucks. 99% of the websites (I have accounts on) rely on my email for recovery and revocation. But my inbox is not an impenetrable fortress, it's a communication channel; every device I own has access to it, and could be used as a backdoor to my entire digital life. Then there's the risk of the third-party (Google banning me, being hacked, subpoena'd, etc), the privacy factor (see the Ashley Ma…

So we can't improve the current situation at all until we solve all the problems?

Re: Yubico and Microsoft Introduce Passwordless Login

#79
post #73

No USB-C version and no way to upgrade my other 4+ YubiKeys I've got for more than $50 each! I think YubiKey has been abusing its monopoly recently! They've been working on this for quite some time and clearly new they're not going to make their old premium keys support it so that people can waste time and money to upgrade! Is there an alternative more conscious company - I'd pay even $200 for the piece of mind that…

I will point out, NitroKey also doesn't have a USB-C version.

True, nobody seems to offer USB-C. Also, I have to point out that YubiKey 4C [0] is not sturdy either unlike the rest - it disintegrated on my keychain in less than two months without any abuse.

[0]: https://www.yubico.com/product/yubikey-4-series/#yubikey-4c

Re: Yubico and Microsoft Introduce Passwordless Login

#80
post #10

Correct me if I am wrong, but passwordless login is a single-factor authentication and less secure than MFA. Depending on whenever hardware key is more or less secure than the password, the mass adoption of this could make things LESS secure.

The biggest win is that you won't get this email anymore (I got this from Twitter recently):

"We recently identified a bug that stored passwords unmasked in an internal log."

Because all they will have is a public key, not your secret password.

Post reply on HN