Live data from Hacker News

YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

yubico.com

81–90 of 187 posts

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#81
post #58

Earlier quoted context omitted.

> U2F can only be used as a second factor. I mean, certificationally, sure. But what prevents a website from trusting you to input your identifier (user name or e-mail address) and then accepting a U2F signed blob as your only credential?

The fact that if someone steaks the key they can impersonate you anywhere. U2F doesn't support pin authentication, as far as I know.

It's not built into the protocol, sure, but the device can do whatever it wants before it decides to sign something. You need to unlock my phone and SEP before Krypton signs anything, for example. But you still raise a good point: I suppose it's a good thing that we can do that with cheaper devices and safe, browser-provided UX for PIN entry.

(I would suggest that a single physical device that takes a PIN before it does some signing is still 2FA even if there is only one _communicated_ credential, but I appreciate we need better terminology for this. Other versions of this to consider: if you username + password + Duo into your SSO portal and then sign into a service with SAML, is that not 2FA? If it isn't, does using a session cookie prevent something from being 2FA? For the latter, I'd say obviously not :-) I think the "who can impersonate you" is a good line in the sand, since in the former the SSO system holds full authority in most cases.)

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#82
post #46
post #39

Earlier quoted context omitted.

Because the something you know part isn't all that secure anyway? https://xkcd.com/538/

it is a different level of security. The comic is fully correct, but you should still use a secret. That is why there are 3 different types of authentication. The first is something you have - a card or key. The second is something you know - a password. The third is something you are - a fingerprint. Each provides protection against a different attack and is vulnerable to different attacks. The more important the se…

> The third is something you are - a fingerprint.

A fingerprint isn't “something you are”, because it can be destroyed while you remain, and information about it can be captured and reproduced by attackers who are not you.

It's just a particularly hard to lose (but easy to discover, and impractical to replace if compromised, at least more times than you have fingers) “something you have.” In security factor terms, I'm not convinced the idea of a distinct “something you are” category is coherent, since most candidates seem similar to that.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#83
post #69

We'll see. There was barely any uptake of FIDO U2F on the web. Sure there were a few major players, like google, but pretty much nothing financial for the public have taken up anything but insecure SMS/call authentication. Meanwhile telcos are working hard to convince the public they should all throw in with their insecure telecos accounts as a chain of trust after time and time again showing that your telco account…

Some actors doing unsafe things should not preclude us from building safe things in the mean while. Google/GSuite accounts matter. GitHub accounts matter.

The problem is that if poor solutions as far as usability are present, you'll have the telecos win.

This is a race against Mobile Authentication Taskforce and their fundamentally insecure accounts. If the solution can't beat them, it'll get trampled.

Those other "unsafe actors" are trying to completely take over authentication, meanwhile you need 2 $50 hardware security keys at a minimum to safely use this tech. This will lose on consumer pricing and consumer uptake to the insecure Mobile Authentication Taskforce and you won't GET the option to use a FIDO2, because you'll have the choice of insecure mobile auth or nothing.

You have to win against the public or they'll be suckered by bad and insecure authentication that is easier to use, and the things you want to use will be insecure anyways.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#84

Earlier quoted context omitted.

I have one of the old blue U2F tokens (~20 EUR), and pretty much only used it for GMail so far. That alone is worth it to me because many other passwords can be reset by someone that gains control over my email account. I personally find the token much more convenient than a TOTP code via app on my smartphone. And the U2F/FIDO part is very interesting as it eliminates phishing as a risk. I ordered a Yubikey 5 NFC jus…

> And the U2F/FIDO part is very interesting as it eliminates phishing as a risk. How does that work? Can't the challenge response be MITM?

The browser sends the domain as part of the request to the U2F key; so a MITM would need to be a true network-level MITM and not just a fake website MITM. The user would then have to ignore the cert error as well.

I'm not saying it's not impossible, but the it's not the primary attack U2F is designed to prevent.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#85
post #24

Honest question, what happens when you lose one of these ?

It’s worth knowing that krypton (https://krypt.co) can make your smartphone act as a U2F or Fido2 (as well as SSH and PGP) device. You can use this instead of a Yubikey, as a backup, or just to inexpensively play with the concept and test out your backup protocols.

Also, some cryptocurrency wallets, like Trezor and the Nano S, can do U2F. These can be effectively backed up to paper with 12 or 24 word seed phrases, and can serve as a good (if bulky) backup option.

Still, save your backup codes for each site you register.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#86
post #67

Earlier quoted context omitted.

The 5C nano is designed to be plugged in the all the time though, so in that scenario what do you really gain from NFC?

Because one day we'd like to securely authenticate to things on phones in phone browsers. (I agree that it's not a big a deal as one may think; it only matters if you're logging in to a critical service via the browser and not the app. If you're using the app, it's the app's problem to make sure that you're talking to the Correct Service(TM), so phishing concerns go away.)

BLE solutions are going to work much better for mobile devices than NFC I think. Google already supports it for their apps via SmartLock and Advanced Protection on both major mobile platforms. Its the browsers, and namely Safari, thats being the blocker on iOS right now - both for NFC and BLE solutions.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#87
post #67

Earlier quoted context omitted.

The 5C nano is designed to be plugged in the all the time though, so in that scenario what do you really gain from NFC?

Because one day we'd like to securely authenticate to things on phones in phone browsers. (I agree that it's not a big a deal as one may think; it only matters if you're logging in to a critical service via the browser and not the app. If you're using the app, it's the app's problem to make sure that you're talking to the Correct Service(TM), so phishing concerns go away.)

That makes sense. I generally don't use my phone to log into anything that requires 2FA, so that didn't even occur to me. For whatever reason, most of the services I use that require 2FA tend to be pretty useless on mobile web.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#88
Just to warn you - although you can put Yubikey 5C on a keychain, it's not robust, and the plastic disintegrates after light use in just months. I had two that got destroyed. Unlike the USB-A, which are highly resilient to wear, the USB-C version are greatly subpar! Given how expensive this is and how important is, it's highly disappointing that they didn't put more thought into the material selection process! Or maybe that was the main idea - make you buy a new key every year.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#89
post #57

I think the YK5's biggest problem is that the YK Neo and 4, which have been out for years, were already so good. Unless you really care about NFC at the same time as RSA-4096, I'm not sure I see a big impetus to upgrade. Hopefully the USB-C line won't be plagued with supply issues. WebAuthn is mostly boring and I think that's mostly a good thing. I'm glad that there's a way to evolve the spec. Some of the changes are…

Just wanted to say thanks for these analysis blubs on HN. Whenever something security related pops up, I rest assured that you or tptacek are going to pop in and tell it how it is.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#90
post #88

Just to warn you - although you can put Yubikey 5C on a keychain, it's not robust, and the plastic disintegrates after light use in just months. I had two that got destroyed. Unlike the USB-A, which are highly resilient to wear, the USB-C version are greatly subpar! Given how expensive this is and how important is, it's highly disappointing that they didn't put more thought into the material selection process! Or may…

Just so you know - I had the same problem but emailed Yubico recently and they said they made some changes because of this defect and sent me a new one for free. It's been at least 2 months and there's been no degradation like my first one.
Post reply on HN