Earlier quoted context omitted.
IMHO the YubiKey is not useful for any of those. It's excellent for storing OpenPGP keys and U2F, reasonably good for X.509 (as much as expected for X.509 I guess), and not good for much else. Using it for TOTP IMHO makes no sense, it's better to use your phone.
Using it for TOTP makes sense if you have more than one phone or want to use TOTP on your desktop through Yubico authenticator.
YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
141–150 of 187 posts
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#142Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#143I think the YK5's biggest problem is that the YK Neo and 4, which have been out for years, were already so good. Unless you really care about NFC at the same time as RSA-4096, I'm not sure I see a big impetus to upgrade. Hopefully the USB-C line won't be plagued with supply issues. WebAuthn is mostly boring and I think that's mostly a good thing. I'm glad that there's a way to evolve the spec. Some of the changes are…
The feature the 4 has which the Neo doesn't which matters most to me is 'touch to confirm key operation' when used via USB. I'm quite surprised how little this seems to be known - a hardware key which will sign anything a potential piece of malware or malicious actor asks for without question (assuming said malware is able to steal the PIN or get access to the appropriate agent socket which is not too much of a stret…
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#144Earlier quoted context omitted.
> the YK Neo and 4, which have been out for years, were already so good I agree that the keys themselves are good; I just wish that configuring Linux systems to take advantage of them would be easier. I've been working on setting my systems up in bits of my free time for more than a month now. I'm in my last stretch, but I have to do some weird things. Maybe I'm just trying to squeeze more out of the key than most wo…
>For example, when I'm in my laptop and I ssh to my desktop and use sudo, I want it to use the key connected to the laptop to authenticate me. At the same time, if I walk over to the desktop and use sudo, I want it to seek the key in the desktop. Same if I use gpg or anything else that wants to use the key. This can easily be done, I do it all the time. You have to set up both YKs to have the same PGP keys and then u…
This effort will also allow me to use gpg and the programs that depend on it like my password manager, pass, to use the correct agent.
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#145Earlier quoted context omitted.
IMHO the YubiKey is not useful for any of those. It's excellent for storing OpenPGP keys and U2F, reasonably good for X.509 (as much as expected for X.509 I guess), and not good for much else. Using it for TOTP IMHO makes no sense, it's better to use your phone.
Using it for TOTP makes sense if you have more than one phone or want to use TOTP on your desktop through Yubico authenticator.
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#146Earlier quoted context omitted.
The 5C nano is designed to be plugged in the all the time though, so in that scenario what do you really gain from NFC?
Because one day we'd like to securely authenticate to things on phones in phone browsers. (I agree that it's not a big a deal as one may think; it only matters if you're logging in to a critical service via the browser and not the app. If you're using the app, it's the app's problem to make sure that you're talking to the Correct Service(TM), so phishing concerns go away.)
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#147Earlier quoted context omitted.
The feature the 4 has which the Neo doesn't which matters most to me is 'touch to confirm key operation' when used via USB. I'm quite surprised how little this seems to be known - a hardware key which will sign anything a potential piece of malware or malicious actor asks for without question (assuming said malware is able to steal the PIN or get access to the appropriate agent socket which is not too much of a stret…
Wait, seriously? Not even the OpenPGP applet/with ykman configuration? In what modes does it do that? That’s send-it-back bad.
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#148I have an iPhone and a Macbook. It's frustrating that I have to choose between USB-C support for the Macbook, and NFC support for the phone. It's odd that they don't make a USB-C version with NFC.
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#149Earlier quoted context omitted.
The feature the 4 has which the Neo doesn't which matters most to me is 'touch to confirm key operation' when used via USB. I'm quite surprised how little this seems to be known - a hardware key which will sign anything a potential piece of malware or malicious actor asks for without question (assuming said malware is able to steal the PIN or get access to the appropriate agent socket which is not too much of a stret…
This makes sense for enterprise uses where an organization wants to keep private key material off a server, but don't want to spend the money for a enterprise security key manager.
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#150Earlier quoted context omitted.
The 5C nano is designed to be plugged in the all the time though, so in that scenario what do you really gain from NFC?
Because one day we'd like to securely authenticate to things on phones in phone browsers. (I agree that it's not a big a deal as one may think; it only matters if you're logging in to a critical service via the browser and not the app. If you're using the app, it's the app's problem to make sure that you're talking to the Correct Service(TM), so phishing concerns go away.)
Once browsers on Android support WebAuthn, it may well be that plugging in a USB-C Yubikey will be more convenient than trying to locate the position of the NFC antenna.