Live data from Hacker News

YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

yubico.com

131–140 of 187 posts

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#131
post #123
post #7

Earlier quoted context omitted.

I don't know how much more ruggerized you need it. It's already pretty dam strong. I've had a neo on my keys for years and it shows no sign of ware. They already are water proof and can be run over by a car. So unless you want to take a hammer to it, it should be rugged enough.

I'd be more concerned about general reliability. How long will these last? Because I think they should last at a minimum 10 years. If you only use one for an account, and it breaks on you, you're screwed. So I would use at least 2, but hopefully websites will allow this, and that will probably be the largest bottleneck in the future. I couldn't care less about "SMS backups" or such nonsense, as that completely defeat…

I configure a second YubiKey as a backup, and disabled SMS-based recovery where possible.

Many sites allow this explicitly, and will let you view details about the last time each key was used to log in.

Some sites that use TOTP only allow for one "authenticator" to be configured. In those cases, I scan the same QR code into each key.

This process requires you to retrieve your backup key from whatever safe place you store it in when configuring 2FA on new accounts, but that feels like a reasonable trade-off; I don't make new accounts very often, and when I do I can wait to configure 2FA until I have access to my backup key.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#133
post #57

I think the YK5's biggest problem is that the YK Neo and 4, which have been out for years, were already so good. Unless you really care about NFC at the same time as RSA-4096, I'm not sure I see a big impetus to upgrade. Hopefully the USB-C line won't be plagued with supply issues. WebAuthn is mostly boring and I think that's mostly a good thing. I'm glad that there's a way to evolve the spec. Some of the changes are…

The feature the 4 has which the Neo doesn't which matters most to me is 'touch to confirm key operation' when used via USB. I'm quite surprised how little this seems to be known - a hardware key which will sign anything a potential piece of malware or malicious actor asks for without question (assuming said malware is able to steal the PIN or get access to the appropriate agent socket which is not too much of a stret…

Wait, seriously? Not even the OpenPGP applet/with ykman configuration? In what modes does it do that? That’s send-it-back bad.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#134
post #60

I have an iPhone and a Macbook. It's frustrating that I have to choose between USB-C support for the Macbook, and NFC support for the phone. It's odd that they don't make a USB-C version with NFC.

It's a few months away, but we'll have usb-c + nfc in Solo (open source security key supporting FIDO2). We'll launch the Kickstarter next week: https://solokeys.com

Very nice. Does it support FIDO2 only or are there other applets (e.g. OpenPGP)?

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#135

Earlier quoted context omitted.

> The third is something you are - a fingerprint. A fingerprint isn't “something you are”, because it can be destroyed while you remain, and information about it can be captured and reproduced by attackers who are not you. It's just a particularly hard to lose (but easy to discover, and impractical to replace if compromised, at least more times than you have fingers) “something you have.” In security factor terms, I'…

"Something you are" is a term of art, not a very specific statement of fact to be legally overanalyzed. A fp is very much "something you are".

> "Something you are" is a term of art,

Yes, what I am saying is that in practice what that term of art refers to is not an independent, orthogonal kind of security factor from “have” and “know” but a strictly worse form of “have”.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#136
post #86
post #67

Earlier quoted context omitted.

Because one day we'd like to securely authenticate to things on phones in phone browsers. (I agree that it's not a big a deal as one may think; it only matters if you're logging in to a critical service via the browser and not the app. If you're using the app, it's the app's problem to make sure that you're talking to the Correct Service(TM), so phishing concerns go away.)

BLE solutions are going to work much better for mobile devices than NFC I think. Google already supports it for their apps via SmartLock and Advanced Protection on both major mobile platforms. Its the browsers, and namely Safari, thats being the blocker on iOS right now - both for NFC and BLE solutions.

> BLE solutions are going to work much better for mobile devices than NFC I think

Yubico would disagree. According to their research studies BLE devices are harder to use and less robust.

Source: https://www.yubico.com/2016/06/yubikey-u2f-tracking-bluetoot...

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#137
post #96

Earlier quoted context omitted.

> The third is something you are - a fingerprint. A fingerprint isn't “something you are”, because it can be destroyed while you remain, and information about it can be captured and reproduced by attackers who are not you. It's just a particularly hard to lose (but easy to discover, and impractical to replace if compromised, at least more times than you have fingers) “something you have.” In security factor terms, I'…

DNA is something you are.

The reason DNA is useful as criminal evidence is you leave it everywhere; that makes it a horrible security factor: like fingerprints it's an impractical to replace wheb compromised “thing you have” that you leave everywhere for attackers.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#138
post #118
post #57

I think the YK5's biggest problem is that the YK Neo and 4, which have been out for years, were already so good. Unless you really care about NFC at the same time as RSA-4096, I'm not sure I see a big impetus to upgrade. Hopefully the USB-C line won't be plagued with supply issues. WebAuthn is mostly boring and I think that's mostly a good thing. I'm glad that there's a way to evolve the spec. Some of the changes are…

> the YK Neo and 4, which have been out for years, were already so good I agree that the keys themselves are good; I just wish that configuring Linux systems to take advantage of them would be easier. I've been working on setting my systems up in bits of my free time for more than a month now. I'm in my last stretch, but I have to do some weird things. Maybe I'm just trying to squeeze more out of the key than most wo…

>For example, when I'm in my laptop and I ssh to my desktop and use sudo, I want it to use the key connected to the laptop to authenticate me. At the same time, if I walk over to the desktop and use sudo, I want it to seek the key in the desktop. Same if I use gpg or anything else that wants to use the key.

This can easily be done, I do it all the time. You have to set up both YKs to have the same PGP keys and then use gpg as your SSH agent.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#139

Earlier quoted context omitted.

How do you enroll a new U2F key to all the websites at once?

It's not possible, unfortunately. So you'll have to do it one by one.

Yes, and it's by design. If you could then one random root key would be sufficient to "restore" all keys (as they are derived from that root key). U2F explicitly doesn't allow that given that the protocol has use counters.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#140
post #62

It is annoying you have to choose between USB-C and NFC. I was really hoping I could have both in a new device. I have a 4C and think it is great - the only downside is the lack of NFC and that only a subset of sites support it, but more are implementing it as time goes on. I'll probably pick up a 5 as one to store on a keyring for mostly NFC use.

Just replied in another thread: it's a few months away, but we'll have usb-c + nfc in Solo (open source security key supporting FIDO2). We'll launch the Kickstarter next week: https://solokeys.com

Will it have all the features of a Yubikey? I have two YubiKeys right now. One with NFC and one USB-C. I would love to just have one, and open source is a plus. I also use the NFC one for 2FA code storage. I then can use my laptop or phone to retrieve a code.
Post reply on HN