Live data from Hacker News

Pressing YubiKeys

bert.org

151–160 of 241 posts

Re: Pressing YubiKeys

#151

Earlier quoted context omitted.

This seemed odd to me as well - anecdata, but I have yet to work at any company that uses YubiKeys, I have only heard that FB does.

FWIW Amazon / AWS also use YubiKeys.

Google as well. (Physical security keys, at least - I make no specific statement about branding)

Re: Pressing YubiKeys

#152
post #147

Earlier quoted context omitted.

If you've got adversaries doing a sun swapping attack you are in a Rick and Morty episode not the real world. I can't swear Google has never known one my phone numbers in the many, many years I've had an account, though they don't have one recorded now. However I can tell you with certainty I have three WebAuthn authenticators, and no SMS-style 2FA authorised on my Google account now.

> If you've got adversaries doing a sun swapping attack you are in a Rick and Morty episode not the real world. It happened to Jack Dorsey. And attacks tend to become easier over time. Any employee of an at&t store could do it to you right now. The reason we know Dorsey was the victim of a sim swap attack is probably that he's important enough that when he was hacked he couldn't be dismissed with the "You probably me…

No, Jack Dorsey suffered a sim swapping attack. Those happen here in the real world, but the post my joke was aimed at wrote sun swapping. Swapping suns isn't a thing outside of fiction.

As to me, since you made it personal, I'm sure somebody at an AT&T store could attempt SIM swapping but they might have trouble because the system won't give them my number from a completely different numbering system (different county) without a code they don't have.

If you socially manipulate your way into getting a transfer out code (good luck with that, but I'm willing to accept it could happen) then the big problem is I don't use SMS 2FA, as I wrote in the comment you're replying to, so it's a dead end.

Re: Pressing YubiKeys

#153
post #120
post #44

Earlier quoted context omitted.

Yeesh $35 for a single button presser?

I mean, for a power supply, bluetooth receiver/chipset, actuator... I don't think I cobble together something half as good for twice as much, and that's not factoring in labor.

It's really about the economies of scale. You can get entire computers for $35.

Re: Pressing YubiKeys

#154
post #100
post #77

Earlier quoted context omitted.

PayPal? All I've ever seen in there is TOTP and SMS

Yes, I meant Yubikey's TOTP with PayPal where the secret is in the hardware. They should ideally support >1 TOTP authenticator if they don't intend to support U2F. I don't want SMS as a backup option; I have deprecated SMS, it's old tech and needs to die along with telegrams.

I’m pretty sure every site I’ve setup to do TOTP only allowed one authenticator. I got burned using Google Authenticator when I had to replace my phone, because there was no way to transfer the auth data to a new phone.

Maybe The Google app has changed now, I have no idea. I’ve had much better luck storing TOTP in 1Password and Bitwarden - which allow you to sync across multiple platforms. So now device upgrades are a non-issue.

Most sites give you some static backup codes for TOTP - definitely store those somewhere safe, they can be a lifesaver.

Re: Pressing YubiKeys

#155
post #147

Earlier quoted context omitted.

> If you've got adversaries doing a sun swapping attack you are in a Rick and Morty episode not the real world. It happened to Jack Dorsey. And attacks tend to become easier over time. Any employee of an at&t store could do it to you right now. The reason we know Dorsey was the victim of a sim swap attack is probably that he's important enough that when he was hacked he couldn't be dismissed with the "You probably me…

No, Jack Dorsey suffered a sim swapping attack. Those happen here in the real world, but the post my joke was aimed at wrote sun swapping. Swapping suns isn't a thing outside of fiction. As to me, since you made it personal, I'm sure somebody at an AT&T store could attempt SIM swapping but they might have trouble because the system won't give them my number from a completely different numbering system (different coun…

hah ok I missed that.

> the system won't give them my number from a completely different numbering system

Perhaps your country has cell phone stores too?

Re: Pressing YubiKeys

#156
post #9

Congratulations, you've defeated the purpose of having a YubiKey

> Congratulations, you've defeated the purpose of having a YubiKey.

Even a virtual 2fa button is useful. It prevents people using your stolen credentials to login to websites unless you click the button, even if it's just a virtual button.

Sure your computer can be compromised, but it's probably still more secure than sms 2fa.

Re: Pressing YubiKeys

#157

Earlier quoted context omitted.

There is also MicroBot: https://microbot.is/push/ I used it for testing smart meters in Norway, so we did not need to run to the lab to trigger events. The best part is that the whole menu is interactive by just one physical button, a great job for a Bluetooth button pusher + Python. It is also capacitive so it work on the phone screen, and YubiKeys (?)

Can you get to the 'buy now' shop on that site?

I have a finger bot do it for me.

Re: Pressing YubiKeys

#158
post #153
post #120

Earlier quoted context omitted.

I mean, for a power supply, bluetooth receiver/chipset, actuator... I don't think I cobble together something half as good for twice as much, and that's not factoring in labor.

It's really about the economies of scale. You can get entire computers for $35.

You can get an entire RPi computer for $10. It all depends on what you call a computer.

Re: Pressing YubiKeys

#159
post #23

Nice build but over engineered. You could achieve the same result by taping a piece of aluminum foil, or maybe even a wire to the capacitive sensor and connecting it to ground through a relay. Use the ESP8266 to toggle the relay when you want to simulate a button press.

That violates corporate IT policy which expressly instructs me to touch the key with one of my fingers.

Re: Pressing YubiKeys

#160

Google won’t let you setup 2FA without adding a phone number which kind of sets you up for sun swapping attack by design... My biggest beef is lack of NFC in MacBook. I wan’t a key in card factor because who the hell has keys these days. Maybe add hardware button on the card. It would work on on mobile and laptops. Banks could use their own credit cards for logging in...

If you've got adversaries doing a sun swapping attack you are in a Rick and Morty episode not the real world. I can't swear Google has never known one my phone numbers in the many, many years I've had an account, though they don't have one recorded now. However I can tell you with certainty I have three WebAuthn authenticators, and no SMS-style 2FA authorised on my Google account now.

Rick did a sim (ulation) swapping attack once or twice too.
Post reply on HN