Live data from Hacker News

Getting a biometric security key right

yubico.com

1–10 of 81 posts

Re: Getting a biometric security key right

#5
A true biometric key would allow authentication from any key and not just a registered key, otherwise it just degrades into a possession authentication factor. A true biometric key would allow you to walk around with absolutely nothing, and doing 2FA using only what you know (password) and what you are (your finger).

Is that possible with this? Could I e.g. pass 2FA on my accounts on a friend's computer using their key with my finger?

Re: Getting a biometric security key right

#6
post #4

There are plenty of fingerprint readers on the market, doesn't really excite me because it just makes it 2-in-1. What does excite me? Smart rings like https://store.nfcring.com/products/omni

Funny enough their own demo (from the parent article) is on a MacBook Air with built-in Touch ID.

Re: Getting a biometric security key right

#7
post #5

A true biometric key would allow authentication from any key and not just a registered key, otherwise it just degrades into a possession authentication factor. A true biometric key would allow you to walk around with absolutely nothing, and doing 2FA using only what you know (password) and what you are (your finger). Is that possible with this? Could I e.g. pass 2FA on my accounts on a friend's computer using their k…

You'd have to trust their key in that case. Otherwise they could be collecting your biometrics for reuse later on. Between trusted friends - probably ok. Secure facility - probably also ok (we already share the fingerprint readers). For public use... I wouldn't touch that.

Re: Getting a biometric security key right

#8
post #5

A true biometric key would allow authentication from any key and not just a registered key, otherwise it just degrades into a possession authentication factor. A true biometric key would allow you to walk around with absolutely nothing, and doing 2FA using only what you know (password) and what you are (your finger). Is that possible with this? Could I e.g. pass 2FA on my accounts on a friend's computer using their k…

Scary - you would have to trust EVERY fingerprint reader not to capture your fingerprint AND you have to trust that you don't leave it anywhere for pickup. It's very hard to change your fingerprint as well, so having images of it out there is not good in general.

Re: Getting a biometric security key right

#9
post #7
post #5

A true biometric key would allow authentication from any key and not just a registered key, otherwise it just degrades into a possession authentication factor. A true biometric key would allow you to walk around with absolutely nothing, and doing 2FA using only what you know (password) and what you are (your finger). Is that possible with this? Could I e.g. pass 2FA on my accounts on a friend's computer using their k…

You'd have to trust their key in that case. Otherwise they could be collecting your biometrics for reuse later on. Between trusted friends - probably ok. Secure facility - probably also ok (we already share the fingerprint readers). For public use... I wouldn't touch that.

[deleted]

Re: Getting a biometric security key right

#10
post #5

A true biometric key would allow authentication from any key and not just a registered key, otherwise it just degrades into a possession authentication factor. A true biometric key would allow you to walk around with absolutely nothing, and doing 2FA using only what you know (password) and what you are (your finger). Is that possible with this? Could I e.g. pass 2FA on my accounts on a friend's computer using their k…

The problem is that your fingerprint is really just a set of information attached your body, similar to a long static password. Not very secure and you can't change it if it was compromised.

The fingerprint on the yubikey is really just a possession check for the yubikey in case it was stolen. The main protection comes from the asymmetric cryptography inside the yubikey.

Post reply on HN