Live data from Hacker News

Yubico launches its dual USB-C and Lightning two-factor security key

techcrunch.com

111–120 of 178 posts

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#111

There's still one huge disadvantage with hardware-based FIDO U2F tokens: There's no good way to migrate from one to another. I've got three(!) Yubikeys of different generations on my keyring because I'm not sure whether I have enrolled the two newer ones to all the services I'm using.

I use 1Password as my password manager, and add a tag to each login where I have a specific hardware key registered.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#112
post #72

Earlier quoted context omitted.

Yeah, I'm annoyed by having to chose between NFC and USB-C. Apparently they're working on it, though: https://twitter.com/Yubico/status/1161003411501748224

https://solokeys.com/ also

Funny enough, their USB/NFC combination device is also USB-A only as well.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#113
post #72

Earlier quoted context omitted.

Yeah, I'm annoyed by having to chose between NFC and USB-C. Apparently they're working on it, though: https://twitter.com/Yubico/status/1161003411501748224

https://solokeys.com/ also

They're sold out :( If you are in SF/Bay area I have a few extra.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#115

Earlier quoted context omitted.

Interesting point - it's essentially a long lived secret. Actually what would happen if [large_comapny] had their TOTP secret revealed? Would they be forced to invalidate everyones TOTP? They can't just disable it they would have to somehow authenticate you a third way....

> Actually what would happen if [large_comapny] had their TOTP secret revealed? Would they be forced to invalidate everyones TOTP? Yes. RSA got hacked for their SecurID information, so that the attackers could then turn around and get into Lockheed Martin: * https://gcn.com/articles/2011/06/07/rsa-confirms-tokens-used... * https://www.scmagazine.com/home/security-news/rsa-confirms-l... Among other things, LM makes th…

Ooh that's interesting! Coincidentally my very close relative works for their F16 program! Yeah they're one of the largest military contractors - not a company anyone wants to have a breach.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#116

> Security keys offer almost unbeatable security and can protect against a variety of threats, including nation-state attackers. Alright, I'm not a security expert, but I'm not completely illiterate to basic computer security. Anyone care to chime in how this is much more secure than a two-factor app? Sure there's the obvious, nobody can just copy the two-factor app off my phone with all the codes and have the same c…

These are basically tiny hardware security modules. The premise of an HSM is that you have a hardened processor that contains the secrets and performs asymmetric crypto operations on request. Ideally, the device is designed such that the secrets never leave a crypto boundary. The big expensive ones will offer facilities to transfer keys, but only over an authenticated, encrypted connection to another device certified by the manufacturer[1].

Yubico has some FIPS certified devices[2], which means that they've presented a design that shows the device has mechanisms to prevent secrets from being extracted, and they're only using algorithms known by NIST not to leak secrets.

> Also pardon me if I confused two-factor as the Google Authenticator app.

Multi-factor authentication is about managing risk, and discussions about risk are naturally fuzzy and vague.

I'll try a concrete analogy; consider firearms safety.

Some typical rules[3]: 1. keep the weapon pointed down range at all times, 2. keep your finger out of the trigger well, 3. treat the weapon as loaded at all times.

Each rule is a factor, and to accidentally hurt someone you have to violate all the rules at once.

Multiple factors work best if they are orthogonal, that is, when a given action results in only breaching a single factor. That's why factors tend to be phrased as "something you know," "something you are," "something you have".

The authenticator app and a Yubikey are doing the exact same thing: they're establishing the "something you have" factor.

Since the two factors work when an attacker must both obtain the device and get your password, if your phone has both passwords and authenticator apps, the additional factors aren't minimizing that risk.

[1]: The automatic vendor lock-in makes it a great business model...

[2]: https://www.yubico.com/business/product/yubikey-fips

[3]: There are many more, but take a class on it rather than depend on the Internet.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#117
post #19

Earlier quoted context omitted.

So far it sounds like the next iPhone will still use lightning, so you should be safe using this Yubikey for a few years at least.

It would be deeply frustrating if Yubico were to spend years coming up with a 2FA product that works with iDevices, and then a few months later Apple were to throw out the interface that product depends on and thus instantly make it completely obsolete. (One would hope that Yubico and Apple have been in touch with each other at least the minimal amount that would be required to avoid such a fiasco. But given Apple's…

It would be a classic Apple move to do that, though, further reinforcing the codependent relationship vendors have had with Apple for decades.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#118
post #93

The Yubikey website is vague, but it seems like the lightning end only works with a few apps (1Password, Brave, etc). What do I do if I want to sign in to anything else that needs 2FA? Do I still need a TOTP app?

From what I've heard from Yubico the next version of iOS is going to make it far easier to communicate with the device. Integrations will probably still need to be added by the app developers though to take full advantage.

"Next version" meaning iOS 13? Or the version after (presumably iOS 14)?

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#119
post #93

The Yubikey website is vague, but it seems like the lightning end only works with a few apps (1Password, Brave, etc). What do I do if I want to sign in to anything else that needs 2FA? Do I still need a TOTP app?

From what I've heard from Yubico the next version of iOS is going to make it far easier to communicate with the device. Integrations will probably still need to be added by the app developers though to take full advantage.

Do you know whether that includes websites in Safari? If I can’t use 2FA for that, I don’t see how I can use a Yubikey.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#120
post #54

Handy table comparing their 5-series options: * https://www.yubico.com/products/yubikey-hardware/compare-yub... Seems the main questions to ask yourself are: * is NFC desired? * do you need/want USB-A or USB-C? This product adds a Lightning option.

Is there no lightning to USB A adapter? Seems a bit wasteful to buy another key for a currently very limited ability in iOS.

While limited today, there are a bunch of applications in beta testing that leverage the key. I personally have a small keychain usb-c to A adapter that I use with my Yubikey Neo. I guess all in they decided a Lightning and USB A option wasn't as smart given most mobile devices are Lightning or USBC moving forward.
Post reply on HN