Live data from Hacker News

YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

yubico.com

91–100 of 187 posts

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#91

I’ve always been fascinated by these, but never had a justifiable reason to get one. The only use I could think of was protecting my LastPass account, but I figured my main risk there is their security getting breached, which Yubico wouldn’t help with.

I have one of the old blue U2F tokens (~20 EUR), and pretty much only used it for GMail so far. That alone is worth it to me because many other passwords can be reset by someone that gains control over my email account. I personally find the token much more convenient than a TOTP code via app on my smartphone. And the U2F/FIDO part is very interesting as it eliminates phishing as a risk. I ordered a Yubikey 5 NFC jus…

On Android there is this https://github.com/zeapo/Android-Password-Store

Works great

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#92
post #69

Earlier quoted context omitted.

Some actors doing unsafe things should not preclude us from building safe things in the mean while. Google/GSuite accounts matter. GitHub accounts matter.

The problem is that if poor solutions as far as usability are present, you'll have the telecos win. This is a race against Mobile Authentication Taskforce and their fundamentally insecure accounts. If the solution can't beat them, it'll get trampled. Those other "unsafe actors" are trying to completely take over authentication, meanwhile you need 2 $50 hardware security keys at a minimum to safely use this tech. This…

You don't need $50 products. You especially don't need two of them.

Yubico already make a Security Key that isn't also a PGP key store, a TOTP authenticator, bagel toaster and whatever else for about $20. And there are cheaper vendors if price is the main concern.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#93
post #86
post #67

Earlier quoted context omitted.

Because one day we'd like to securely authenticate to things on phones in phone browsers. (I agree that it's not a big a deal as one may think; it only matters if you're logging in to a critical service via the browser and not the app. If you're using the app, it's the app's problem to make sure that you're talking to the Correct Service(TM), so phishing concerns go away.)

BLE solutions are going to work much better for mobile devices than NFC I think. Google already supports it for their apps via SmartLock and Advanced Protection on both major mobile platforms. Its the browsers, and namely Safari, thats being the blocker on iOS right now - both for NFC and BLE solutions.

It works in iOS Chrome but only on Google properties. I agree Safari is a problem, I’m not sure it’s the only pinch point. They managed to glue it all together with app links and URL schemes.

(Chrome on iOS works fine with Krypton on the same phone, effectively giving me the SEP U2F I want, just with gross UX.)

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#94
post #69

Earlier quoted context omitted.

Some actors doing unsafe things should not preclude us from building safe things in the mean while. Google/GSuite accounts matter. GitHub accounts matter.

The problem is that if poor solutions as far as usability are present, you'll have the telecos win. This is a race against Mobile Authentication Taskforce and their fundamentally insecure accounts. If the solution can't beat them, it'll get trampled. Those other "unsafe actors" are trying to completely take over authentication, meanwhile you need 2 $50 hardware security keys at a minimum to safely use this tech. This…

You can get a U2F device that lives in your phone’s SEP, right now, for free. U2F kegs are not $50.

https://krypt.co/

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#95
post #11
post #8

Earlier quoted context omitted.

IIRC the NEO only does TOTP over NFC. It sounds like the 5 does U2F over NFC, now?

Oh, interesting! That's not called out on their comparison chart for the NEO. That would certainly be a tempting upgrade for any NEO users then

Now I've only got one problem remaining: how do I upgrade my old U2F-capable NEO on all the websites? Do I have to keep it with me ad infinitum? I cannot really destroy it either, as I cannot be 100 % sure I've remembered to enroll my new Yubikey 5.

This raises a more generic question: What's the proper upgrade path for hardware authentication tokens?

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#96
post #46

Earlier quoted context omitted.

it is a different level of security. The comic is fully correct, but you should still use a secret. That is why there are 3 different types of authentication. The first is something you have - a card or key. The second is something you know - a password. The third is something you are - a fingerprint. Each provides protection against a different attack and is vulnerable to different attacks. The more important the se…

> The third is something you are - a fingerprint. A fingerprint isn't “something you are”, because it can be destroyed while you remain, and information about it can be captured and reproduced by attackers who are not you. It's just a particularly hard to lose (but easy to discover, and impractical to replace if compromised, at least more times than you have fingers) “something you have.” In security factor terms, I'…

DNA is something you are.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#97
I'm a LastPass user using Yubikey nanos for both my work and home PCs. But I would like to purchase a Windows 2-in-1 that only has a single USB-C port used for charging and thus a nano wouldn't really work out well. Since Yubikeys, including these latest 5 series, do not support bluetooth, most Windows laptops don't support NFC, and LastPass does not support FIDO/U2F (so Google's Titan bluetooth won't work), is my only option to unplug the charger, plug in the USB-C Yubikey, and plug the charger back in every time I want to log into LastPass? I'm kind of an end user with this sort of stuff...

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#98
post #88

Just to warn you - although you can put Yubikey 5C on a keychain, it's not robust, and the plastic disintegrates after light use in just months. I had two that got destroyed. Unlike the USB-A, which are highly resilient to wear, the USB-C version are greatly subpar! Given how expensive this is and how important is, it's highly disappointing that they didn't put more thought into the material selection process! Or may…

Just so you know - I had the same problem but emailed Yubico recently and they said they made some changes because of this defect and sent me a new one for free. It's been at least 2 months and there's been no degradation like my first one.

Thanks for the info! I'm glad that fixed this. I will reach out to them today as I migrated off the old key long ago. If they replace it, I will give it to my 10-year-old son, who uses my old keys. :)

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#99

I'm a LastPass user using Yubikey nanos for both my work and home PCs. But I would like to purchase a Windows 2-in-1 that only has a single USB-C port used for charging and thus a nano wouldn't really work out well. Since Yubikeys, including these latest 5 series, do not support bluetooth, most Windows laptops don't support NFC, and LastPass does not support FIDO/U2F (so Google's Titan bluetooth won't work), is my on…

LastPass Enterprise supports Duo, which then allows you to use FIDO/UTF there if you enable in the DUO admin panel.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#100
post #57

I think the YK5's biggest problem is that the YK Neo and 4, which have been out for years, were already so good. Unless you really care about NFC at the same time as RSA-4096, I'm not sure I see a big impetus to upgrade. Hopefully the USB-C line won't be plagued with supply issues. WebAuthn is mostly boring and I think that's mostly a good thing. I'm glad that there's a way to evolve the spec. Some of the changes are…

> Unless you really care about NFC at the same time as RSA-4096, I'm not sure I see a big impetus to upgrade

Agreed, it looks more like the new keys main draw is feature consistency across the whole YK5 line. You can now select the form factor you want and, aside from NFC, it has the same features as the other form factors. With YK4, there was not nearly the same feature parity across form factors.

Post reply on HN