Live data from Hacker News

Yubico and Microsoft Introduce Passwordless Login

yubico.com

91–100 of 218 posts

Re: Yubico and Microsoft Introduce Passwordless Login

#91
post #86

The conversation here is blowing my mind. People are actually worried that their yubikey might get lost or stolen when likely most of your passwords are already all over the internet. I got an email from Twitter just a few days ago stating that they'd leaked my password. Twitter! Not Joe's Auto-Body who's website is being run by a high-schooler, but one of the pioneers of internet companies. They messed up. Your pass…

> I got an email from Twitter just a few days ago stating that they'd leaked my password

Clearly you didn't read the email.

The password was potentially logged to twitter's servers in plaintext.

They have no evidence anyone collected those passwords, but various employees could, in theory, have seen those logs.

Presumably those logs are now all deleted.

Even if you didn't reset your twitter password, it's very likely you'd be fine since it's not "leaked" (to the wider internet), but could have been seen by some employees who, for fear of being fired, no doubt did not save it (and in all likelyhood didn't see it in the first place).

Re: Yubico and Microsoft Introduce Passwordless Login

#92
post #91
post #86

The conversation here is blowing my mind. People are actually worried that their yubikey might get lost or stolen when likely most of your passwords are already all over the internet. I got an email from Twitter just a few days ago stating that they'd leaked my password. Twitter! Not Joe's Auto-Body who's website is being run by a high-schooler, but one of the pioneers of internet companies. They messed up. Your pass…

> I got an email from Twitter just a few days ago stating that they'd leaked my password Clearly you didn't read the email. The password was potentially logged to twitter's servers in plaintext. They have no evidence anyone collected those passwords, but various employees could, in theory, have seen those logs. Presumably those logs are now all deleted. Even if you didn't reset your twitter password, it's very likely…

You obviously are more trusting than I am. Also, my point was that if Twitter messed up, so has every other website. Do you trust them all as much as you trust the Twitter employees?

Re: Yubico and Microsoft Introduce Passwordless Login

#93
post #86

The conversation here is blowing my mind. People are actually worried that their yubikey might get lost or stolen when likely most of your passwords are already all over the internet. I got an email from Twitter just a few days ago stating that they'd leaked my password. Twitter! Not Joe's Auto-Body who's website is being run by a high-schooler, but one of the pioneers of internet companies. They messed up. Your pass…

so basically to defend against password hacking they want to use FIDO/yubikeys.

Too bad if something like twitter happens your yubikey is probably useless after it would've prolly logged anything to their servers.

P.S.: it's possible to change passwords, but hardware keys need to be destroyed and changed. Also Yubikeys can also have bugs. https://www.yubico.com/2017/10/infineon-rsa-key-generation-i... So basically it's not more secure. even worse the more code you throw at a problem the more likely it is to be unsecure.

Re: Yubico and Microsoft Introduce Passwordless Login

#94
post #88

Would be interesting if this would become popular one downside I see to this is that if law enforcement get their hands on your token they can unlock the device. Also as the token can be regarded as a key rather than a password a court would be able to legally compel you to surrender it without invoking much debate regarding laws against self incrimination (e.g. the fifth).

Can't law enforcement now just ask Google or Facebook or whoever for the information they need without needing your password (or future token)?

It's not that simple, firstly some Google and Facebook services are E2E encrypted which means that they cannot comply.

This also goes well beyond just Facebook and Google and if you use it to lock a physical device like a phone or a laptop that isn't something Google or Facebook would be able to help law enforcement with.

Also while I don't want to make a statement or start a debate on the level of compliance and attitude that Google and the rest have towards search warrants (because it's not relevant and I don't have sufficient knowledge to actually form an informed opinion on the matter). Google and Facebook's legal departments have more funding than most state attorneys yet alone local DA's if they want to fight on your behalf (or on the behalf of their business model) in court they would be able to do so much more effectively than you ever could.

Google and Facebook also require a full and lengthy process with FIDO tokens they can do it on the spot, heck they are legally able to do so if you either agree to a search or law enforcement has an alternative sufficient basis to invoke a lawful warrantless search:

https://en.wikipedia.org/wiki/Warrantless_searches_in_the_Un...

TLDR; Officer: May I search your vehicle You: Yes

At that point they are legally are allowed to take the FIDO token from your keychain and unlock your laptop.

Re: Yubico and Microsoft Introduce Passwordless Login

#95
post #89
post #86

The conversation here is blowing my mind. People are actually worried that their yubikey might get lost or stolen when likely most of your passwords are already all over the internet. I got an email from Twitter just a few days ago stating that they'd leaked my password. Twitter! Not Joe's Auto-Body who's website is being run by a high-schooler, but one of the pioneers of internet companies. They messed up. Your pass…

Still reading the comments, but is anyone actually saying passwords are more secure in general? I think most people are saying that they get locked out of their account if they lose the token. How do you validate your account is your account if the only secret you have is lost? If you 100% require a hardware token, you need at least two and/or a method to auth that is not a hardware token so you can recover in a mode…

"Security from the people directly around you and security from everyone on the internet." Are the people around you not on the internet? They are just a subset of that larger group, aren't they? Sorry if I'm not understanding your point there.

And like I said in my edit, I really hope that Yubikey is not the one and only one way to store private keys. I personally would be perfectly happy, for most websites and apps, to manage keys just like I do for ssh. On my hard drive, backed up to another hard drive or two of mine, protected by a passphrase. I imagine most people would be pretty comfortable letting a service like lastpass manage most of their private keys for them, with multiple copies synced between devices and encrypted with a strong passphrase.

Re: Yubico and Microsoft Introduce Passwordless Login

#96
post #9

Two things - is there really need for them to be this large? They also look vulnerable? Maybe its just the look, but the blue one looks like it won't survive proper stress test... And second thing - is exposing connector safe against mechanical damage? Will it withstand constantly being scratched by keys?

Let me share with you an anecdote from a friend of mine:

Lost my YubiKey around the start of the year and couldn't understand how it could have disappeared so I deregistered it everywhere and went back to Google Authenticator. Found it today [July] embedded in my gravel driveway where it must have been since January and been stepped on/run over since then. Popped it into the computer mostly for fun, and it works like a charm. :P Hardy stuff! :)

Re: Yubico and Microsoft Introduce Passwordless Login

#97
post #93
post #86

The conversation here is blowing my mind. People are actually worried that their yubikey might get lost or stolen when likely most of your passwords are already all over the internet. I got an email from Twitter just a few days ago stating that they'd leaked my password. Twitter! Not Joe's Auto-Body who's website is being run by a high-schooler, but one of the pioneers of internet companies. They messed up. Your pass…

so basically to defend against password hacking they want to use FIDO/yubikeys. Too bad if something like twitter happens your yubikey is probably useless after it would've prolly logged anything to their servers. P.S.: it's possible to change passwords, but hardware keys need to be destroyed and changed. Also Yubikeys can also have bugs. https://www.yubico.com/2017/10/infineon-rsa-key-generation-i... So basically it…

Um, if we use public key cryptography, the only thing websites can log or leak is your public key. Since it's public, that doesn't break anything.

Re: Yubico and Microsoft Introduce Passwordless Login

#98
post #15

Earlier quoted context omitted.

There is the "nano" version available which is a lot smaller than the one advertised. The ones that I own have held up just fine for the past year on my keychain. https://www.yubico.com/product/yubikey-4-series/#yubikey-4-n...

Do previous YubiKeys support FIDO2? From the post, I assume you need one of the new ones.

The NEO and 4 series support U2F which can be used for FIDO2 2FA (emphasis on 2), but they do not support the passwordless (device PIN) or username-less login scenarios.

Re: Yubico and Microsoft Introduce Passwordless Login

#99
post #45

Earlier quoted context omitted.

> But hopefully U2F will actually work in non-Chrome browsers in the near future. I would guess you're referring to being able to log in to gmail (or anything in G Suite) with U2F from Firefox. U2F is already available in the most recent version. See "security.webauth.*" keys in about:config. It just won't work with Google, at least not yet. Google's implementation predates webauth by a pretty fair margin, and from w…

It’s almost as if we shouldn’t deviate from standards just to get features out of the door faster

Isn't it more about pioneering and experimenting in order to inform and stabilize the standards? My understanding is that many new and upcoming protocols are the result of experimentation in the wild. SPDY/http2/quic/etc?

Re: Yubico and Microsoft Introduce Passwordless Login

#100
post #97
post #93

Earlier quoted context omitted.

so basically to defend against password hacking they want to use FIDO/yubikeys. Too bad if something like twitter happens your yubikey is probably useless after it would've prolly logged anything to their servers. P.S.: it's possible to change passwords, but hardware keys need to be destroyed and changed. Also Yubikeys can also have bugs. https://www.yubico.com/2017/10/infineon-rsa-key-generation-i... So basically it…

Um, if we use public key cryptography, the only thing websites can log or leak is your public key. Since it's public, that doesn't break anything.

accept that your public key is useless if twitter accidently logs challenges. or even worse your hardware is useless if key generation is too weak. or even more worse the protocol is so complex that chances are high that even implementations can contain bugs. or ...

most engineers have trouble implementing simple logins with password. do you really think that having a complex system will be better?

Post reply on HN