Could a username + U2F token be used as authentication?
YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
181–187 of 187 posts
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#182How many e.g. gmail accounts can be supported on a single key? I've got probably five gmail accounts.
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#183Earlier quoted context omitted.
Then buy a fireproof document safe and put all those documents in there.
Off topic: I feel like a fireproof document safe is something that I should own, but every time I shop for one I find myself going down a rabbit hole of unfamiliar terminology and certifications. As with many things, it seems like the marketing for such safes doesn't always match the fine print. (And sometime the fine print just seems impractical: I'm unlikely to actually air out my safe for 30 minutes each week, but…
Look for UL fire endurance ratings. UL rates them on time and temperature. Edit: I've seen ratings up to 3 hours, but the longer the time, the bulkier and heavier for the same storage volume.
For paper, you'd want something rated to stay below 350 degrees for at least an hour. That's not hard to find even in large sizes. I ended up with a used FireKing 4 drawer file cabinet from a company liquidation sale. Edit: Built like a tank, holds a lot, uses a Medeco key, weighs a couple hundred pounds empty.
For digital, you need something rated to stay below 125 degrees. That's pretty hard to find, and usually only in very small boxes. Unfortunately, some companies (looking at you, Sentry) like to advertise "digital media" boxes which are not rated for 125 when you read the fine print. Not sure how they get away with that. :(
I eventually found a small Sentry chest rated for 125 degrees for 30 minutes. Holds a couple hard drives and some DVDs. Sadly, do not recall the model number. Edit: Storage volume is maybe 5"x5"x8", walls are all 3-4" thick.
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#184It is annoying you have to choose between USB-C and NFC. I was really hoping I could have both in a new device. I have a 4C and think it is great - the only downside is the lack of NFC and that only a subset of sites support it, but more are implementing it as time goes on. I'll probably pick up a 5 as one to store on a keyring for mostly NFC use.
Just replied in another thread: it's a few months away, but we'll have usb-c + nfc in Solo (open source security key supporting FIDO2). We'll launch the Kickstarter next week: https://solokeys.com
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#185Earlier quoted context omitted.
I use an app based 2FA for that. Maybe I’ll look into a YubiKey though. My problem is that I’m halfway in my own personal transition from USB A to USB C
I wish you successful personal transition, why you skipped USB B ?
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#186Earlier quoted context omitted.
I use an app based 2FA for that. Maybe I’ll look into a YubiKey though. My problem is that I’m halfway in my own personal transition from USB A to USB C
App based 2FA is still more vulnerable to phishing than a U2F key, because it relies on the user to check they are entering the code into the right website. It's also faster and easier (no pulling out your phone, getting a code, typing it in, just touch the key). Plus, the keys have other features (GPG keys, etc...) which can be useful.
Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
#187Earlier quoted context omitted.
Oh, interesting! That's not called out on their comparison chart for the NEO. That would certainly be a tempting upgrade for any NEO users then
Now I've only got one problem remaining: how do I upgrade my old U2F-capable NEO on all the websites? Do I have to keep it with me ad infinitum? I cannot really destroy it either, as I cannot be 100 % sure I've remembered to enroll my new Yubikey 5. This raises a more generic question: What's the proper upgrade path for hardware authentication tokens?
This is the reason why I'm still using only a password manager. I agree that a hardware token more security but the lost/stolen/change key problem is really not easy right now.
I hope there will be a new common API to change all enrollment you have done but it seems hard as the key don't even know them.
Maybe in a future version ?