Live data from Hacker News

YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

yubico.com

31–40 of 187 posts

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#31

This is fantastic! I'm super psyched about this. > Works on Microsoft Windows, macOS, Linux and on major browsers such as Chrome, Firefox, Safari, Edge, and Opera [1] I looked everywhere for documentation of Safari support but came up empty-handed. Does anyone know where this is documented? I've been waiting for this since forever. [1]: https://www.yubico.com/product/yubikey-5-nfc/

It should also work with Vivaldi (From the makers of Opera) and tries to make a more modern Opera 12. Vivaldi uses chrome extensions. I still see some people using Opera and they never switched to Vivaldi.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#32

I’ve always been fascinated by these, but never had a justifiable reason to get one. The only use I could think of was protecting my LastPass account, but I figured my main risk there is their security getting breached, which Yubico wouldn’t help with.

I have one of the old blue U2F tokens (~20 EUR), and pretty much only used it for GMail so far. That alone is worth it to me because many other passwords can be reset by someone that gains control over my email account.

I personally find the token much more convenient than a TOTP code via app on my smartphone. And the U2F/FIDO part is very interesting as it eliminates phishing as a risk.

I ordered a Yubikey 5 NFC just now to play around especially with the NFC part and see if I can do something useful on my phone with that. I'm still looking for a password manager that could use an NFC Yubikey to unlock it on a smartphone.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#33
post #24

Honest question, what happens when you lose one of these ?

For 2FA, having multiple of these or some kind of recovery code tends to be the answer, as you can remove the keys from sites you use it on.

I am less willing to use something like this for passwordless logins. These types of devices should be part of the "something you have" part of 2FA, which should always be paired with a "something you know".

Maybe I'm missing a step here, but why would you ever use this for passwordless?

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#34
post #24

Honest question, what happens when you lose one of these ?

I’ve had the same concern for a long time, but more from a worry about what to do when it breaks or stops working after a few years. The recommendations I’ve read are to always have a recovery key or other alternate mechanisms that don’t depend on this device. One common suggestion also seems to be to print the recovery/alternate key and keep it safe.

I believe this is a bigger barrier for common people who don’t know how to create and retain backup mechanisms. As such, I don’t see a lot of value in recommending these devices to those who aren’t tech savvy without also explaining to them about recovery. So much for technology!

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#35
post #7

Earlier quoted context omitted.

I don't know how much more ruggerized you need it. It's already pretty dam strong. I've had a neo on my keys for years and it shows no sign of ware. They already are water proof and can be run over by a car. So unless you want to take a hammer to it, it should be rugged enough.

> I don't know how much more ruggerized you need it. It's already pretty dam strong. I've had a neo on my keys for years and it shows no sign of ware. The first batch of the 4Cs were notoriously fragile. The plastic would break within a few months of normal use.

I was unaware, but I guess that sorta makes sense. I have only done with USB A style, which is an Epoxied PCB which makes it fairly hard to break.

USB C has a connector that cannot just be the PCB, and so it needs a housing and such.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#36
post #24

Honest question, what happens when you lose one of these ?

It's smart to buy two at the same time. While you can't copy a Yubikey, you can choose how to initialize them and you can initialize both identical to one another and then lock them down. That way they're copies of one another and fully backed up. I keep my main one on me at all times and have my backup in a safe place.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#37
post #31

This is fantastic! I'm super psyched about this. > Works on Microsoft Windows, macOS, Linux and on major browsers such as Chrome, Firefox, Safari, Edge, and Opera [1] I looked everywhere for documentation of Safari support but came up empty-handed. Does anyone know where this is documented? I've been waiting for this since forever. [1]: https://www.yubico.com/product/yubikey-5-nfc/

It should also work with Vivaldi (From the makers of Opera) and tries to make a more modern Opera 12. Vivaldi uses chrome extensions. I still see some people using Opera and they never switched to Vivaldi.

That happens to be the very browser I'm using now, but Vivaldi support doesn't surprise me, given that it's built on Chromium. I love Safari and will continue to use it every day, but the previous (?) lack of U2F support was (is?) a drag.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#38
post #24

Honest question, what happens when you lose one of these ?

It's smart to buy two at the same time. While you can't copy a Yubikey, you can choose how to initialize them and you can initialize both identical to one another and then lock them down. That way they're copies of one another and fully backed up. I keep my main one on me at all times and have my backup in a safe place.

Do you have a link to the docs that shows this? From what I can find on their site [1] it only supports a few of the protocols:

-Static Password

-HMAC-SHA1 Challenge-Response

-OATH-TOTP (Yubico Authenticator)

[1] https://support.yubico.com/support/solutions/articles/150000...

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#39
post #33
post #24

Honest question, what happens when you lose one of these ?

For 2FA, having multiple of these or some kind of recovery code tends to be the answer, as you can remove the keys from sites you use it on. I am less willing to use something like this for passwordless logins. These types of devices should be part of the "something you have" part of 2FA, which should always be paired with a "something you know". Maybe I'm missing a step here, but why would you ever use this for pass…

Because the something you know part isn't all that secure anyway?

https://xkcd.com/538/

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#40
post #24

Honest question, what happens when you lose one of these ?

Yubikey has a lot of features (applets) built-in so the answer is "it depends on what you use".

U2F? You need to have a second one or backup codes.

OpenPGP? You probably have your subkeys backed up somewhere so you just order a new Yubikey and put your subkeys there.

The same goes to PIV (X.509 certs). If you have some keys generated on the card, you need to provision your new Yubikey from the beginning.

Post reply on HN