Live data from Hacker News

Yubico launches its dual USB-C and Lightning two-factor security key

techcrunch.com

151–160 of 178 posts

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#151

Strong advise anyone considering putting one of these on their keychains to consider otherwise. The actual connector of my usb-c version has warped in my pocket over time and it’s now not recognised.

The USB-A version is great. I've been using it for more than a year now and it has taken all kinds of abuse.

I'm considering keeping it and using a small USB-C -> USB-A dongle. I have to live a dongle life anyway (because of the stupid Apple decision to go all-in on USB-C, with users as hostages), so it doesn't matter that much.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#152
post #69

Earlier quoted context omitted.

Fastmail allows you to do this too. They have a long section in the documentation that strongly discourages it, and it seems like they will refuse to restore your account if you lose your 2FA, which is exactly what I want: https://www.fastmail.com/help/account/2fa.html >> Why do I have to add a recovery phone number to set up two-step verification? > Keeping your account safe from attackers is very important. But so…

Fastmail used to have a mechanism where you could hold down (I believe) on that screen and phone number would no longer be a required field to continue creating your account. Maybe that's still possible.

This was still possible as of March of this year. I was instructed to hold down on Mac.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#153
post #129
post #13

Earlier quoted context omitted.

Simple: security keys combat phishing, two-factor apps do not. A security key doesn't just authenticate you to a site: it also authenticates the site to you.

I think I get what you are trying to express, but rather than "it authenticates the site to you", I think that should be phrased "it prevents you from authenticating at a site pretending to be some other site. evil.com can still claim to be mysite.com and trick users into using their security key there, no? It would presumably have to trick the user into "registering again" since there is no valid key handle for FIDO…

Suppose the key allows mysite.com to let you see your emails, send more emails, and send money to people, etc. Basically mysite.com let's you see and do interesting things after you've authed.

Even if evil.com gets you to register and present your key, they cannot forward it to mysite.com. Even if they go to all the trouble to completely mitm you and the site looks identical to mysite.com, they cannot get the emails or get it to send money.

This is because evil.com cannot pretend to be you when they interact with mysite.com no matter what you've given them.

It's going to be hard to trick me into thinking I've logged into my gmail if none of my emails are there!

Unless they somehow convince you to put your yubikey in the mail and physically send it to them...

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#154
post #103

Earlier quoted context omitted.

Yes, but the key space to brute force is the key space after truncation. You don’t need to brute force the original seed.

If an attacker can (for whatever reason, be it rate limiting or cost) only brute force 100 guesses per time period (say, 30s), they'll expect to be able to 'win' the challenge in about 58 hours. The probability of guessing the challenge _wrong_ once is (1 - (100 / 1000000)). Every 30 seconds you get another chance. The probability of guessing the challenge wrong N times in a row is (1 - (100/1000000)) ^ N. Around cha…

At some point the 2FA protected system should stop accepting guesses entirely for a period - the same way you would lock an account for incorrect password guesses, or at worst rate limit down to a single guess per time period after a certain number of failed guesses.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#155
I was an early, enthusiastic adopter of Yubikeys at my work. Above and beyond the other issues people have mentioned, though, the one that kills the product for me is the frankly stupid OS integration. The key behaves like “just” a special kind of keyboard which types a long string of gibberish and then hits enter any time you touch the trigger.

I can’t tell you how many times I have accidentally bumped the thing and thereby entered my secret key in:

- text editors - the URL bar of my browser (!) - Slack chats (!!)

The solution seems obvious to me: make a new type of input field at the browser and OS level which accepts U2F input, then reject that input in any text field that doesn’t opt in.

This one issue has made the key way more of a liability than a simple authenticator app for me.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#156
post #155

I was an early, enthusiastic adopter of Yubikeys at my work. Above and beyond the other issues people have mentioned, though, the one that kills the product for me is the frankly stupid OS integration. The key behaves like “just” a special kind of keyboard which types a long string of gibberish and then hits enter any time you touch the trigger. I can’t tell you how many times I have accidentally bumped the thing and…

What are you talking about? The default configuration definitely does not type your secret key, but a one time password.

The entire point of the default configuration is that the secret key is stored only on the device and never leaves it.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#157
post #155

I was an early, enthusiastic adopter of Yubikeys at my work. Above and beyond the other issues people have mentioned, though, the one that kills the product for me is the frankly stupid OS integration. The key behaves like “just” a special kind of keyboard which types a long string of gibberish and then hits enter any time you touch the trigger. I can’t tell you how many times I have accidentally bumped the thing and…

What are you talking about? The default configuration definitely does not type your secret key , but a one time password. The entire point of the default configuration is that the secret key is stored only on the device and never leaves it.

I should clarify: the secret key should never leave the device after configuration is completed.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#158
post #155

I was an early, enthusiastic adopter of Yubikeys at my work. Above and beyond the other issues people have mentioned, though, the one that kills the product for me is the frankly stupid OS integration. The key behaves like “just” a special kind of keyboard which types a long string of gibberish and then hits enter any time you touch the trigger. I can’t tell you how many times I have accidentally bumped the thing and…

The macOS YubiSwitch app solves that problem nicely. https://support.yubico.com/support/solutions/articles/150000...

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#159
post #155

I was an early, enthusiastic adopter of Yubikeys at my work. Above and beyond the other issues people have mentioned, though, the one that kills the product for me is the frankly stupid OS integration. The key behaves like “just” a special kind of keyboard which types a long string of gibberish and then hits enter any time you touch the trigger. I can’t tell you how many times I have accidentally bumped the thing and…

If you’re not using both slots you can move the credential to slot 2 so that it requires a long press before it activates

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#160
post #126

Earlier quoted context omitted.

Short version: the FIPS is for enterprise. The Security Key is for consumers. The 5 series is for enterprise or power users. This might be more useful for you: https://www.yubico.com/products/yubikey-hardware/compare-pro... You want the Yubikey FIPS if you're using it in a context where FIPS compliance matters, such as US government. If not (such as for personal use), then don't bother. The Security Key series is the…

The Yubikey requires a password by default to use the ssh key stored on it and it will lock itself after 3 failed attempts. So I don’t think your caveat is valid. I rather have my encryption key on hardware design to keep anyone who finds it from brute forcing it than just password protected on a hard drive.

It can also be configured to require a touch for every signing action or even one for multiple signing actions within a 15 second window I think it is
Post reply on HN