Live data from Hacker News

Pressing YubiKeys

bert.org

101–110 of 241 posts

Re: Pressing YubiKeys

#101
post #59
post #8

Adaprox has various "finger bots" for those who don't want to build their own: https://www.adaprox.io/

I like the concept but the price is steep IMO. $90 for two actuators in the starter kit then $40 for each additional module. I wonder if one could design a similar solution without requiring a bridge. Although of course given the power consumption adding WiFi on the actuators might not be a great idea.

The cost appears to be higher to cover the development/systems cost for the app?

Re: Pressing YubiKeys

#102
The Bloomberg terminal uses a piece of hardware that generates 2FA tokens, but requires you to scan your fingerprint each time. So we need a fake finger that also has my fingerprint, and a webcam pointed at the 2FA hardware, so I can just get my auth keys remotely and not need to carry around another dongle.

Re: Pressing YubiKeys

#103
"So.. you built a button that you press that will press a button? Why not just press the button?” which was a bit infuriating because they clearly missed the whole point. “Don’t you get it? This button BAD, but this button GOOD. Me want to press GOOD button.”"

This is gold.

Re: Pressing YubiKeys

#104
post #9

Congratulations, you've defeated the purpose of having a YubiKey

Yeah... isn't one benefit of a yubikey that a secret must be acquired by some very physical and intentional means? If my laptop/password is compromised, then they still can't log in because they need my secret token from the yubikey. Well, if having that secret token is just one curl call away if they're on the same network then its no longer a very physical and intentional safeguard.

I know... layers of unlikelihood.. but I'd probably opt for a physical "good button" gapped from my computer as sort of a closed electrical extension of my finger.

Re: Pressing YubiKeys

#105
post #45

Earlier quoted context omitted.

Considering many services only allow one YubiKey or only one TOTP authenticator ... I might actually need a short term solution like this to beat the 2FA on those services. Otherwise what happens if I lose my key on the road? The 2FA services that allow >1 YubiKey are good, I can have a backup key locked up some place and use them as intended.

You use the backup keys the service gave you when you enabled 2FA.

Those backup keys defeat the entire purpose of 2FA and are like storing passwords in plain text. It only takes 1, maybe 2 of those codes for an attacker to add another security key to your account for future unlimited access.

Supporting multiple keys is a better solution.

Re: Pressing YubiKeys

#106
post #94
post #75

Earlier quoted context omitted.

There are these RSA-brand tokens that show a new TOTP number every few minutes. Occasionally people find an unsecured webcam pointed at one of those somewhere on the internet...

This was a crazy idea I had one day. I'm glad to see that other people have taken the liberty of executing my crazy ideas so that I don't have to.

https://thedailywtf.com/articles/the-robot-guys

Re: Pressing YubiKeys

#107
Ways they could solve their problem without significantly compromising security:

1. Plug the yubikey into the monitor

2. Use an extension cord (as they did)

3. Switch back to an otp app (eg Google authenticator or Duo)

4. Credit to conk [1] or agl [2]: extend the conductivity via conductive foil or other material, connect to ground to simulate touch

Ways you can improve convenience while reducing security:

1. This!

2. Disable 2fa (credit to another commenter)

If 2fa is required by your company, circumventing it by eliminating the security benefit should be severely reprimanded.

Why not build a different shitty robot?

[1] https://news.ycombinator.com/item?id=24664842

[2] https://news.ycombinator.com/item?id=24664881

Re: Pressing YubiKeys

#108

Earlier quoted context omitted.

I remember a story about how our (third party) security operations center doesn’t allow phones on the floor, but most of its customers use Duo Push. So there is a table in the middle of the floor with all the 2FA phones bolted to it.

I don't understand the threats, risk, or solution here.

i think it's just an amusing anecdote because phones aren't usually bolted to tables.

Re: Pressing YubiKeys

#109
post #54
post #45

Earlier quoted context omitted.

Considering many services only allow one YubiKey or only one TOTP authenticator ... I might actually need a short term solution like this to beat the 2FA on those services. Otherwise what happens if I lose my key on the road? The 2FA services that allow >1 YubiKey are good, I can have a backup key locked up some place and use them as intended.

Looking at you, AWS.

Twitter as well

Re: Pressing YubiKeys

#110
Urban myth: somebody taped a hotdog to the CD drive tray of their workstation, and put the yubikey right in front of it. Then, whenever they needed to touch the YK while not physically in front of the workstation, a quick `eject /dev/cdrom` did the trick ;)
Post reply on HN