Live data from Hacker News

YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

yubico.com

21–30 of 187 posts

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#21
post #14

The difference between WebAuthn and U2F isn't really clear to me, but I hope the older generations will continue to work with common browser's FIDO2 implementations for a long time to come. YubiKeys are great, but too expensive to replace on a whim every year.

U2F can only be used as a second factor. FIDO2 can be used as a replacement for a username/password, so you can go to a site, insert your FIDO2 key and log in without any other information. Old Yubikeys only support U2F, and there's a Yubico FIDO2 key. Browser support isn't there yet, I've been trying to write a Django library for it but no browser will support the complete FIDO2 flow as far as I know.

> FIDO2 can be used as a replacement for a username/password, so you can go to a site, insert your FIDO2 key and log in without any other information.

Technically U2F can be used to design passwordless scheme too (returning a big array of all key handles known to a service) but FIDO2 probably has some optimizations in this area.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#22
post #20

Earlier quoted context omitted.

U2F can only be used as a second factor. FIDO2 can be used as a replacement for a username/password, so you can go to a site, insert your FIDO2 key and log in without any other information. Old Yubikeys only support U2F, and there's a Yubico FIDO2 key. Browser support isn't there yet, I've been trying to write a Django library for it but no browser will support the complete FIDO2 flow as far as I know.

Ah, that's perfect. A hardware token as the /only/ factor sounds like a bridge too far anyhow.

I don't know, it sounds perfect to me.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#23
I’ve always been fascinated by these, but never had a justifiable reason to get one.

The only use I could think of was protecting my LastPass account, but I figured my main risk there is their security getting breached, which Yubico wouldn’t help with.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#25

I’ve always been fascinated by these, but never had a justifiable reason to get one. The only use I could think of was protecting my LastPass account, but I figured my main risk there is their security getting breached, which Yubico wouldn’t help with.

Github and google support u2f. If you are a gmail user you should get a u2f device to protect your email.

That said the cheaper yubi do this as well. I use my yubi 4 for securing my ssh key as well though this is a) a pain & b) likely theater.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#26
post #7

I look forward for a more robust and durable hardware design. Maybe a ruggerized version?

I don't know how much more ruggerized you need it. It's already pretty dam strong. I've had a neo on my keys for years and it shows no sign of ware. They already are water proof and can be run over by a car. So unless you want to take a hammer to it, it should be rugged enough.

> I don't know how much more ruggerized you need it. It's already pretty dam strong. I've had a neo on my keys for years and it shows no sign of ware.

The first batch of the 4Cs were notoriously fragile. The plastic would break within a few months of normal use.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#27

I’ve always been fascinated by these, but never had a justifiable reason to get one. The only use I could think of was protecting my LastPass account, but I figured my main risk there is their security getting breached, which Yubico wouldn’t help with.

Github and google support u2f. If you are a gmail user you should get a u2f device to protect your email. That said the cheaper yubi do this as well. I use my yubi 4 for securing my ssh key as well though this is a) a pain & b) likely theater.

I use an app based 2FA for that.

Maybe I’ll look into a YubiKey though. My problem is that I’m halfway in my own personal transition from USB A to USB C

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#28
post #24

Honest question, what happens when you lose one of these ?

You should have backup 2FA methods for that case, either more tokens at different locations or other 2FA methods like TOTP or printed one-time backup codes or all of these together.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#29

I’ve always been fascinated by these, but never had a justifiable reason to get one. The only use I could think of was protecting my LastPass account, but I figured my main risk there is their security getting breached, which Yubico wouldn’t help with.

Github and google support u2f. If you are a gmail user you should get a u2f device to protect your email. That said the cheaper yubi do this as well. I use my yubi 4 for securing my ssh key as well though this is a) a pain & b) likely theater.

[deleted]
Post reply on HN