Live data from Hacker News

Yubico launches its dual USB-C and Lightning two-factor security key

techcrunch.com

21–30 of 178 posts

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#21

> Security keys offer almost unbeatable security and can protect against a variety of threats, including nation-state attackers. Alright, I'm not a security expert, but I'm not completely illiterate to basic computer security. Anyone care to chime in how this is much more secure than a two-factor app? Sure there's the obvious, nobody can just copy the two-factor app off my phone with all the codes and have the same c…

> whose to stop someone from cloning a Yubico key? That is precisely what these devices are designed to stop. The device has a private key stored in hardware in a way that it cannot be retrieved by software. When you use one of these devices you dramatically decrease your number of attack vectors because now the attack has to happen physically. Someone has to actually steal your physical key. And because this is your…

Impresive, have they had external security firms try to steal the private key? Thats my final thought.

I guess it makes sense. By the time an adversary gets your key you would of noticed and have locked that key from your account.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#22

Earlier quoted context omitted.

> whose to stop someone from cloning a Yubico key? That is precisely what these devices are designed to stop. The device has a private key stored in hardware in a way that it cannot be retrieved by software. When you use one of these devices you dramatically decrease your number of attack vectors because now the attack has to happen physically. Someone has to actually steal your physical key. And because this is your…

Impresive, have they had external security firms try to steal the private key? Thats my final thought. I guess it makes sense. By the time an adversary gets your key you would of noticed and have locked that key from your account.

> have they had external security firms try to steal the private key?

Definitely, it's an expensive vulnerability to simply reveal though. YubiKeys are proprietary so they can't be audited by non-contracted third parties. There are FOSS security keys that don't have that problem though.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#23

Earlier quoted context omitted.

> whose to stop someone from cloning a Yubico key? That is precisely what these devices are designed to stop. The device has a private key stored in hardware in a way that it cannot be retrieved by software. When you use one of these devices you dramatically decrease your number of attack vectors because now the attack has to happen physically. Someone has to actually steal your physical key. And because this is your…

I didn't know about 1Pass, I've been a paying member for a while. I'll try that out! But to put a finer point on your actual statement, I usually screenshot the MFA setup in case my phone gets lost, so I can easily re-set it up.

With SAASPASS Authenticator you can set up recovery in case you lose your or change your phone.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#24
post #15

That sounds nice. But while using U2F/FIDO for a few years (with two HyperFIDOs, one for "daily" use attached to my key-chain, the other as a backup in a safe), I found the most common problem was that websites/services don't tread these keys as first class citizens. For example GitHub: I have my two keys setup there, but I can't opt-out of SMS authentication. If I knew I could use my keys at more services, I would a…

Last year I got the Google Titan security keys and connected it with all of my work + personal accounts that support it.

The #1 weakness is the simple fact that many services don't allow you to disable alternate forms of 2fa.

Github is an example, you can always trigger the fallback SMS 2fa code.

Dashlane is another example (and arguably the most important). It's impossible to make your security key the only form of 2-FA. If you have a security key on your account, you must also have regular app-based 2-FA enabled as a fall back.

What's the point of using security keys with services that require regular SMS or app-based 2-FA as a fallback?

Edit: G Suite is one of the few services that got it right. G Suite has an optional security control that when enabled, forces authentication using security keys (explicitly forbidding alternate 2-fa methods).

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#25
post #13

> Security keys offer almost unbeatable security and can protect against a variety of threats, including nation-state attackers. Alright, I'm not a security expert, but I'm not completely illiterate to basic computer security. Anyone care to chime in how this is much more secure than a two-factor app? Sure there's the obvious, nobody can just copy the two-factor app off my phone with all the codes and have the same c…

Simple: security keys combat phishing, two-factor apps do not. A security key doesn't just authenticate you to a site: it also authenticates the site to you.

Security keys are two factor as well. In fact there are multiple different types of 2FA with different security levels. SMS 2FA is one of the weakest. Push Login is moderate. Scanning encrypted barcodes is highest and also phishing proof like FIDO keys.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#26
post #10
post #6

I think I'd preferred if they offered a USB-C and USB-A combo.

Something like this would suffice, if it was simple to keep along side the key: https://tripplite.com/usb-c-female-to-usb-a-male-adapter~U32...

I was looking into something like this, and while this probably works fine these aren't allowed under the USB spec, so you're hoping whoever designed these did it right and its not going to misbehave with some devices.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#27
post #19
post #14

Just out of curiosity, is Apple migrating away from Lightning toward USB-C? $70 for one key is a bit steep especially if Apple eventually shelves Lightning on iPhones.

So far it sounds like the next iPhone will still use lightning, so you should be safe using this Yubikey for a few years at least.

It would be deeply frustrating if Yubico were to spend years coming up with a 2FA product that works with iDevices, and then a few months later Apple were to throw out the interface that product depends on and thus instantly make it completely obsolete.

(One would hope that Yubico and Apple have been in touch with each other at least the minimal amount that would be required to avoid such a fiasco. But given Apple's penchant for secrecy, who knows?)

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#28
post #9

Check out solokeys, though they're doing a hardware revision for the usb-c since it was flimsy and some NFC changes due to power draw

Solokeys are great. They also have a crowdsupply for a smaller form factor version (USB-A only for now):

https://www.crowdsupply.com/solokeys/somu

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#29
post #19

Earlier quoted context omitted.

So far it sounds like the next iPhone will still use lightning, so you should be safe using this Yubikey for a few years at least.

It would be deeply frustrating if Yubico were to spend years coming up with a 2FA product that works with iDevices, and then a few months later Apple were to throw out the interface that product depends on and thus instantly make it completely obsolete. (One would hope that Yubico and Apple have been in touch with each other at least the minimal amount that would be required to avoid such a fiasco. But given Apple's…

[deleted]
Post reply on HN