Live data from Hacker News

Pressing YubiKeys

bert.org

111–120 of 241 posts

Re: Pressing YubiKeys

#111
post #74

The final thoughts at the end of the article are amazing: "Why not just press the button?" ... "Don’t you get it? This button BAD, but this button GOOD. Me want to press GOOD button."

So that GOOD button presses BAD button.

All the sins and bad karma falls on the GOOD button. It is our martyr and savior. It sacrifices its purity for us.

Re: Pressing YubiKeys

#112
post #81

"If you work in tech, you probably have a YubiKey" The author must live in some kind of bubble. This may only be true at Big Tech companies or other companies with a atypically strong security focus.

Used to have some (actually, I still do, in a drawer) but gave up on them several years ago after random mysterious failures - just going dead after a few months. I hope for their customers' sakes they have solved their reliability problem.

My experience is quite contrary to yours - those things are indestructible... Mine even survived a machine wash.

Re: Pressing YubiKeys

#114

Earlier quoted context omitted.

I remember a story about how our (third party) security operations center doesn’t allow phones on the floor, but most of its customers use Duo Push. So there is a table in the middle of the floor with all the 2FA phones bolted to it.

I don't understand the threats, risk, or solution here.

> I don't understand the threats, risk, or solution here.

john_travolta.gif

Re: Pressing YubiKeys

#115
post #110

Urban myth: somebody taped a hotdog to the CD drive tray of their workstation, and put the yubikey right in front of it. Then, whenever they needed to touch the YK while not physically in front of the workstation, a quick `eject /dev/cdrom` did the trick ;)

It's all good until you consider the need to periodically replace the hotdog every day or two, as it gets rotten at room temperature.

Re: Pressing YubiKeys

#116

"If you work in tech, you probably have a YubiKey" The author must live in some kind of bubble. This may only be true at Big Tech companies or other companies with a atypically strong security focus.

Yeah, that seems a little myopic. I've worked at more places without YubiKeys than with them.

Edit: To be clear, I've had plenty of _other_ 2FA devices.

Re: Pressing YubiKeys

#118
Google won’t let you setup 2FA without adding a phone number which kind of sets you up for sun swapping attack by design...

My biggest beef is lack of NFC in MacBook. I wan’t a key in card factor because who the hell has keys these days. Maybe add hardware button on the card. It would work on on mobile and laptops. Banks could use their own credit cards for logging in...

Re: Pressing YubiKeys

#119
post #110

Urban myth: somebody taped a hotdog to the CD drive tray of their workstation, and put the yubikey right in front of it. Then, whenever they needed to touch the YK while not physically in front of the workstation, a quick `eject /dev/cdrom` did the trick ;)

It's all good until you consider the need to periodically replace the hotdog every day or two, as it gets rotten at room temperature.

Well, considering that you don't have to actually be at your desk anymore, you can let it rot for a couple of weeks between replacements. Or use some other material with similar conductivity and capacitance characteristics.

Re: Pressing YubiKeys

#120
post #44
post #8

Adaprox has various "finger bots" for those who don't want to build their own: https://www.adaprox.io/

Yeesh $35 for a single button presser?

I mean, for a power supply, bluetooth receiver/chipset, actuator... I don't think I cobble together something half as good for twice as much, and that's not factoring in labor.
Post reply on HN