Live data from Hacker News

Yubico launches its dual USB-C and Lightning two-factor security key

techcrunch.com

61–70 of 178 posts

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#61
Is there any security cards that just use NFC (with physical button, obviously)?

I think government issued cards are good contender for this. Perhaps it could even replicate certificate authority chain principles - certain cards could sign other cards and then can be invalidated if compromised.

My local id card is absolutely pathetic. I have no idea where to get a reader (although they are generic) and worst part is requirement to run Java applet in your browser - something that has been dead for over 10 years...

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#62
post #15

That sounds nice. But while using U2F/FIDO for a few years (with two HyperFIDOs, one for "daily" use attached to my key-chain, the other as a backup in a safe), I found the most common problem was that websites/services don't tread these keys as first class citizens. For example GitHub: I have my two keys setup there, but I can't opt-out of SMS authentication. If I knew I could use my keys at more services, I would a…

I’m not sure what you mean. I have SMS and Fallback SMS both disabled: https://imgur.com/a/bLnRuOq

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#63

Is there any security cards that just use NFC (with physical button, obviously)? I think government issued cards are good contender for this. Perhaps it could even replicate certificate authority chain principles - certain cards could sign other cards and then can be invalidated if compromised. My local id card is absolutely pathetic. I have no idea where to get a reader (although they are generic) and worst part is…

> I think government issued cards are good contender for this.

For this, devices would have to support real NFC in the first place. iPhones/iPads don't allow app usage of NFC, and the flagship Samsung tablets don't ship with it at all.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#64

Is there any security cards that just use NFC (with physical button, obviously)? I think government issued cards are good contender for this. Perhaps it could even replicate certificate authority chain principles - certain cards could sign other cards and then can be invalidated if compromised. My local id card is absolutely pathetic. I have no idea where to get a reader (although they are generic) and worst part is…

> I think government issued cards are good contender for this. For this, devices would have to support real NFC in the first place. iPhones/iPads don't allow app usage of NFC, and the flagship Samsung tablets don't ship with it at all.

Most modern Android phones, or at least the Samsung ones and probably Google ones I have used, allow for virtually full read/write NFC access as far as I can tell.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#65
post #53
post #15

That sounds nice. But while using U2F/FIDO for a few years (with two HyperFIDOs, one for "daily" use attached to my key-chain, the other as a backup in a safe), I found the most common problem was that websites/services don't tread these keys as first class citizens. For example GitHub: I have my two keys setup there, but I can't opt-out of SMS authentication. If I knew I could use my keys at more services, I would a…

In addition to what you're saying, I also would like to register multiple keys to services such that any one would work, not that both are required. I don't need them to be nuclear keys... I want a backup key stored in a safe and one on my keychain. This seems to be very uncommon amongst service providers.

I’d say this is actually the most common. I’m not aware of any websites that allow >1 U2F/FIDO key in the configuration where you need to use all-of-them to log in. Sites either only support 1 key, or support multiple keys and you need 1 of them to log in.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#66

Is there any security cards that just use NFC (with physical button, obviously)? I think government issued cards are good contender for this. Perhaps it could even replicate certificate authority chain principles - certain cards could sign other cards and then can be invalidated if compromised. My local id card is absolutely pathetic. I have no idea where to get a reader (although they are generic) and worst part is…

> I think government issued cards are good contender for this. For this, devices would have to support real NFC in the first place. iPhones/iPads don't allow app usage of NFC, and the flagship Samsung tablets don't ship with it at all.

In iOS 13 they opened up the APIs. Not clear what that's going to mean yet for Yubikey and etc.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#67
post #19

Earlier quoted context omitted.

So far it sounds like the next iPhone will still use lightning, so you should be safe using this Yubikey for a few years at least.

It would be deeply frustrating if Yubico were to spend years coming up with a 2FA product that works with iDevices, and then a few months later Apple were to throw out the interface that product depends on and thus instantly make it completely obsolete. (One would hope that Yubico and Apple have been in touch with each other at least the minimal amount that would be required to avoid such a fiasco. But given Apple's…

Current iPhones will at least be commonly in circulation for a few years, so it wouldn't be a complete waste.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#68

Is there any security cards that just use NFC (with physical button, obviously)? I think government issued cards are good contender for this. Perhaps it could even replicate certificate authority chain principles - certain cards could sign other cards and then can be invalidated if compromised. My local id card is absolutely pathetic. I have no idea where to get a reader (although they are generic) and worst part is…

What would the benefits of NFC cards be? To me it seems more insecure given that anybody walking closely by could theoretically communicate with the card.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#69
post #24
post #15

That sounds nice. But while using U2F/FIDO for a few years (with two HyperFIDOs, one for "daily" use attached to my key-chain, the other as a backup in a safe), I found the most common problem was that websites/services don't tread these keys as first class citizens. For example GitHub: I have my two keys setup there, but I can't opt-out of SMS authentication. If I knew I could use my keys at more services, I would a…

Last year I got the Google Titan security keys and connected it with all of my work + personal accounts that support it. The #1 weakness is the simple fact that many services don't allow you to disable alternate forms of 2fa. Github is an example, you can always trigger the fallback SMS 2fa code. Dashlane is another example (and arguably the most important). It's impossible to make your security key the only form of…

Fastmail allows you to do this too. They have a long section in the documentation that strongly discourages it, and it seems like they will refuse to restore your account if you lose your 2FA, which is exactly what I want:

https://www.fastmail.com/help/account/2fa.html

>> Why do I have to add a recovery phone number to set up two-step verification?

> Keeping your account safe from attackers is very important. But so too is making sure you don't get locked out of your own account. We are aware that SMS is not the most secure of methods for 2FA, and has been deprecated by NIST. However, for the majority of users, the risk of losing their two-step verification device is far greater than the risk of someone hacking their SMS. If you lose your phone, the TOTP key is lost but normally you can get a new SIM card with the same number from your carrier. We therefore believe requiring a phone as a backup option strikes the best balance of confidentiality (no one else can read your data) and availability (you can read your data) for the majority of our users.

> Please note, if two-step verification is enabled, access to the phone number itself is not sufficient to gain access to an account: you still need two factors (your password AND the SMS).

> Advanced users that understand the risk may remove the phone number from their account once two-step verification is enabled. Once the recovery phone is removed from the account, SMS is no longer an option as the second factor for login. If you choose to do this, we strongly recommend you write down or print your recovery code and store it in a safe location, and that you set up at least two security keys or authenticator devices. Should you lose access to all two-step verification devices and not have your recovery code, you may be permanently locked out of your own account.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#70

> Security keys offer almost unbeatable security and can protect against a variety of threats, including nation-state attackers. Alright, I'm not a security expert, but I'm not completely illiterate to basic computer security. Anyone care to chime in how this is much more secure than a two-factor app? Sure there's the obvious, nobody can just copy the two-factor app off my phone with all the codes and have the same c…

Speaking as someone who writes code for authentication systems, it's not marketing hype. These physical U2F authenticators are more secure by design than the number based authenticator apps.

Since the Yubikey (and friends) operates by generating a private key on the device itself, inaccessible to software, it means that the key is hard to clone. They'd have to steal it off your person. Combined with generating a unique key pair for every website and checking that the website is what it claims to be, this means that the key is resistant to replay attacks, which number based authenticator apps are vulnerable to.

That isn't to say that it's immune to phishing, but it's much, much harder to phish someone who is using a Yubikey because an attacker would need to compromise someone's DNS configuration or SSL configuration to impersonate the website, at which point... why are they bothering with phishing?

Post reply on HN