Live data from Hacker News

Getting a biometric security key right

yubico.com

71–80 of 81 posts

Re: Getting a biometric security key right

#71

What happens if I lose the key, I don't have it on me, or if I'm using a mobile UI? It seems like you need an identifier (email/username/etc) besides the hardware key for this to be practical.

I currently use a yubikey for as much as I can, so here is what I have: 1) My yubikey has NFC and works fine with my phone. Even that webauthn website demo works in a mobile browser via NFC. 2) For TOTP secrets, I enroll them in both my yubikey and in the Aegis android app. I mainly use these with the Yubico Authenticator software for windows or linux, but I can pull out my phone if I need to. 3) For any account that…

U2F is freaking awesome. It's rare to have something which is both high security and not a pain to use.

I just wish the banking and financial industry would get onboard. For customer accounts, they are mostly using SMS, but some of them are still using personal info question (e.g. what was your first pets name) as a second factor which is horrible.

Re: Getting a biometric security key right

#72
post #69
post #38

Earlier quoted context omitted.

> The fingerprint on the yubikey is really just a possession check for the yubikey in case it was stolen. And one that only depends on the tamper-resistance of the hardware. It's possible to use error correcting codes to extract deterministic secrets from fuzzy data like fingerprints, but no one (virtually no one?) implements that. Instead, the fingerprinte reader has some cleartext fingerprint fingerprints that it c…

It is interesting to compare the security of a yubikey+pin vs yubikey+fingerprint. Both provide similar and really good security compared to popular authentication mechanisms like static password, sms, and even authenticator apps. But a sophisticated attack could still use your credentials if the yubikey was stolen, and the attacker had your fingerprint (plausible with the OPM personal info leak) or had captured your…

Personally I prefer just using multiple Yubikeys, one left permanently in each device, never carry one a loose key around, and if one is stolen, just deactivate that key from all services.

Having to carry a loose key around is a liability.

Re: Getting a biometric security key right

#75
post #69
post #38

Earlier quoted context omitted.

> The fingerprint on the yubikey is really just a possession check for the yubikey in case it was stolen. And one that only depends on the tamper-resistance of the hardware. It's possible to use error correcting codes to extract deterministic secrets from fuzzy data like fingerprints, but no one (virtually no one?) implements that. Instead, the fingerprinte reader has some cleartext fingerprint fingerprints that it c…

It is interesting to compare the security of a yubikey+pin vs yubikey+fingerprint. Both provide similar and really good security compared to popular authentication mechanisms like static password, sms, and even authenticator apps. But a sophisticated attack could still use your credentials if the yubikey was stolen, and the attacker had your fingerprint (plausible with the OPM personal info leak) or had captured your…

> It seems like the most secure method (albeit impractical) would be to have a "what you know" challenge built into the yubikey, like a pin pad or dial. At that point though, one would probably have to worry about other attacks, like physical intrusion and kidnapping as well.

This isn't uncommon for Bitcoin hardware wallets, fwiw.

But the problem is that the short what you know challenge isn't very secure if the edge device is compromised and can't impose rate limiting or maximum-try limits.

I think for auth I'd rather have yubi/fingerprint + password. Yes, the host could still the password, but even if the yubi is completely backdoored you still have a credible amount of security.

It would be better still if the fingerprint mechanism were cryptographic. But it's probably pretty hard to fit a lot of fancy code in such a small device, -- and security is something of a lemon market (see also zoom's "end to end").

I think people should be extremely wary of efforts to turn U2f devices into single factor authentication. If intelligence agencies haven't compromised yubico or at least developed a good program to substitute devices in the mail-- then they ought to be fired.

Re: Getting a biometric security key right

#76
post #42

Earlier quoted context omitted.

If possible can you point out resident keys in the spec? This is confusing. > For each account on a given site, you'll have an independent RK. Is this only for usernameless sites? Sites with usernames can just use normal keys, right? > (But the only sites where you can use RKs are basically Microsoft or demos.) How do sites request to use RK’s? Why would Microsoft request RK’s when they can use the associated email a…

> can you point out resident keys in the spec The WebAuthn specification calls this a "Client-side-resident Public Key Credential Source" or "Resident Credential" for short. > Is this only for usernameless sites? It facilitates the "usernameless" flow yes, since the Resident Credential includes everything needed for the authenticator to claim you are some particular user and prove it. But it will still work for other…

Hmm, usernameless with resident keys doesn’t seem all that great to me then. Thanks for the info!

Re: Getting a biometric security key right

#77
post #65

Earlier quoted context omitted.

> Does it worth repeating that "fingerprints are usernames, not passwords"? No, because that is nonsense. Fingerprints are something different to both usernames and passwords. They aren't the same as either of them. For example you can change both passwords and usernames but you can't change a fingerprint. Also fingerprints are more difficult to discover than usernames.

> No, because that is nonsense. Fingerprints are something different to both usernames and passwords. In The Netherlands you can be forced to give your fingerprint to unlock your smartphone. You cannot be forced to unlock your smartphone via PIN, or share your password. > For example you can change both passwords and usernames but you can't change a fingerprint. Yes, you can. Your fingerprint can be unreadable under…

> In The Netherlands you can be forced to give your fingerprint to unlock your smartphone. You cannot be forced to unlock your smartphone via PIN, or share your password.

Ok that's why I said fingerprints are different to passwords?

> Your fingerprint can be unreadable under circumstances. With sandpaper you can remove it.

Please don't nitpick. You don't really think I didn't know that.

> Inaccurate, and untrue. They're all over the place.

Your username is `Fnoord`. How can I get your fingerprint just as easily? I did not say it is very difficult to get someone's fingerprint if you want, just that it is harder than getting a username. You can just ask people for their usernames, people will usually give them out to strangers. Try that with fingerprints.

In fact, if it is just as easy to get a username as a fingerprint, here's my username: IshKebab. Now can you find my fingerprint?

Re: Getting a biometric security key right

#78
post #65

Earlier quoted context omitted.

> No, because that is nonsense. Fingerprints are something different to both usernames and passwords. In The Netherlands you can be forced to give your fingerprint to unlock your smartphone. You cannot be forced to unlock your smartphone via PIN, or share your password. > For example you can change both passwords and usernames but you can't change a fingerprint. Yes, you can. Your fingerprint can be unreadable under…

> In The Netherlands you can be forced to give your fingerprint to unlock your smartphone. You cannot be forced to unlock your smartphone via PIN, or share your password. Ok that's why I said fingerprints are different to passwords? > Your fingerprint can be unreadable under circumstances. With sandpaper you can remove it. Please don't nitpick. You don't really think I didn't know that. > Inaccurate, and untrue. They…

> Please don't nitpick. You don't really think I didn't know that.

You wrote "but you can't change a fingerprint". Its inaccurate.

> In fact, if it is just as easy to get a username as a fingerprint, here's my username: IshKebab. Now can you find my fingerprint?

The context is smartphones. If I had physical access to you, no problem. [1]

[1] https://www.wired.com/2008/03/hackers-publish/

Re: Getting a biometric security key right

#79
post #18

Earlier quoted context omitted.

U2F is a second factor, not a primary one.

While this is true, the spirit of the GP is correct. To login you will need both a username/password and the second factor. So losing the key is still relevant. In practice that means people really need to buy (at least) two yubikeys to register with services that allow it. Have one on something that’s always with you (such as keys) and the extra(s) as a backup somewhere secure. Unfortunately this works with most acc…

To sidestep this, create a new AWS account to be your master SSO administration account (separate from whatever account you're already using), and enable "AWS Organizations" in it. Join the existing AWS accounts to the new "AWS Organization".

Once you enable AWS SSO for the "organization", you can then set up SAML SSO to your existing identity provider (e.g. G Suite, which allows multiple hardware 2FA tokens per user). You do this in the new master organization account.

You can create the corresponding users in AWS SSO, and grant them the appropriate permissions in the appropriate organization accounts.

Then you do the 2FA auth to your IdP (G Suite, or selfhosted, or whatever) and then AWS just trusts the auth from the IdP, and you get to sidestep the terrible morass that is AWS MFA configuration.

If you get stuck, email me.

Re: Getting a biometric security key right

#80
post #22

What happens if I lose the key, I don't have it on me, or if I'm using a mobile UI? It seems like you need an identifier (email/username/etc) besides the hardware key for this to be practical.

FIDO2 supports password-less and username-less authentication, both as a single factor, i.e. no passwords. Password-less is like 2FA but without the first factor. You type in your username, next you use the security key. Username-less is done via resident keys, that can also store the username at registration. The whole experience is just authenticating with the security key. If you use FIDO without a password (not a…

If you're using it as a resident key (username+password) then what happens if you lose that key? How can I recover my account? I don't even know my username or my password. That seems like an oversight in the spec.
Post reply on HN