Live data from Hacker News

Pressing YubiKeys

bert.org

11–20 of 241 posts

Re: Pressing YubiKeys

#12
This is some cowboy engineering and i love it. totally shooting from the hip, but still finishing up with a nice long-form post. like other comments mentioned this is super impractical but that's not the point. building a robot finger to push a button at the push of a button is a hilarious saturday afternoon project

good job bert!

Re: Pressing YubiKeys

#18
The final thoughts at the end of the article are amazing:

"Why not just press the button?" ... "Don’t you get it? This button BAD, but this button GOOD. Me want to press GOOD button."

Re: Pressing YubiKeys

#19
The obvious next step is to plug this into a server and control it through USB over IP. Call it "remote, centrally controlled 2FA" and your manager will love it!

Re: Pressing YubiKeys

#20
post #13

Earlier quoted context omitted.

Not in practice. The odds any malware would both locate this api, and actionably utilize a generated otp, is slim to zero.

sounds like security through obscurity.

Right. And that isn't a problem for some threat models.
Post reply on HN