Live data from Hacker News

That's not how 2FA works

shkspr.mobi

81–90 of 269 posts

Re: That's not how 2FA works

#81
post #70

Earlier quoted context omitted.

I think Yubikey (and similar physical solutions) will eventually gain popularity. Carrying a key is pretty much a standard practice across the globe and benefit is more than negligible because it forces physical attack versus remote/virtual.

Instead of a hardware authenticator to be carried on a keyring, they should be put into rings, i.e., the things meant to be worn on your fingers, i.e., the things that most people use for providing input to their computing devices, whether they sit on a desk or are held in one's hands.

I had one twenty years ago, a Java Ring. Apparently they are still being made today.

Re: That's not how 2FA works

#82

Earlier quoted context omitted.

For the reasons listed in the article and more, Yubikeys and similar devices aren’t likely to ever be popular. To give future security devices along the same vain a better chance at gaining popularity and being widely adopted (which will hopefully bringing us a more stable, less stressful society), the designs of these new devices must solve or workaround the issues the author describes. It’s really annoying when ind…

I think Yubikey (and similar physical solutions) will eventually gain popularity. Carrying a key is pretty much a standard practice across the globe and benefit is more than negligible because it forces physical attack versus remote/virtual.

Until keys become cloneable they will never gain popularity.

Nobody wants to re-setup every site ever because they lost their laptop that they kept it plugged into, so they won't. either this means using their backup until they lose it without even revoking the original and then swearing off the entire concept while telling all their friends to do the same, or just not using hardware tokens after the first lost of keys.

Also the "back up code" they will also get, guess where thats going! save as -> downloads or print2pdf -> downloads.

When it comes to personal account security by end users, hardware tokens will never take off, and this is why they get so much hate.

There is a real problem here that really needs to be really solved, wrt to end users and phishing/hack resistant credentials, and as long as we legitimize the lie that yubikey solves it, we gimp progress towards actually solving it.

Re: That's not how 2FA works

#83
post #19

The Yubikey/WebAuthn comments are really ignorant and discouraging people from the best defense against this sort of attack that exists. First of all you can get WebAuthn devices for as little as $10 now. Second, there is no app to configure. You plug it in when it says register and tap it. Done. Third, if the WebAuthn device gets stolen the attacker presumably lacks a password. You can't use the device by itself. Al…

For the reasons listed in the article and more, Yubikeys and similar devices aren’t likely to ever be popular. To give future security devices along the same vain a better chance at gaining popularity and being widely adopted (which will hopefully bringing us a more stable, less stressful society), the designs of these new devices must solve or workaround the issues the author describes. It’s really annoying when ind…

> I’m not a moderator, but I ask you to please try to better further the discussion with future comments.

Please don't go there. You're both adding to the discussion, maybe some strong words here and there, but this turn of phrase you used is a huge conversation destroyer.

Re: That's not how 2FA works

#84
post #19

The Yubikey/WebAuthn comments are really ignorant and discouraging people from the best defense against this sort of attack that exists. First of all you can get WebAuthn devices for as little as $10 now. Second, there is no app to configure. You plug it in when it says register and tap it. Done. Third, if the WebAuthn device gets stolen the attacker presumably lacks a password. You can't use the device by itself. Al…

Plus, iPhones already support webauthn via Face ID, and I assume MacBooks will support it via Touch ID at some point.

Re: That's not how 2FA works

#85
post #19

The Yubikey/WebAuthn comments are really ignorant and discouraging people from the best defense against this sort of attack that exists. First of all you can get WebAuthn devices for as little as $10 now. Second, there is no app to configure. You plug it in when it says register and tap it. Done. Third, if the WebAuthn device gets stolen the attacker presumably lacks a password. You can't use the device by itself. Al…

Disappointed but not surprised when reading this. To be really honest, I can't remember the last time I read something that criticized so called "techbros" and actually said something reasonable.

As for the U2F devices, the idea of just leaving them in, the small yubikeys and all that, seem to just be a bad idea from the get-go.

Re: That's not how 2FA works

#86
post #55
post #21

Earlier quoted context omitted.

YubiKey recommended that I install Yubi Auth https://play.google.com/store/apps/details?id=com.yubico.yub... and YubiClip https://play.google.com/store/apps/details?id=com.yubico.yub... Should I not have?

If you had used one of the $10 USD Webauthn (aka U2F) tokens, it wouldn't have asked you to install any applications. The "problem" is the expensive Yubikeys that you were whining about has lots of extra functionality that has nothing to do with U2F, and that's what the extra applications are all about. I happen to use a Yubikey because I want that extra functionality, including using it to secure the keys I use for…

OpenSSH >= 8.something natively supports U2F. No need for extra functionality.

Re: That's not how 2FA works

#87
post #80
post #78

This is a weird post. Yubikeys are absolutley the solution here, also a password manager. A decent password manager will check the URL for you.

There are many legitimate situations in which a login domain is changed and a password manager no longer works. So then you manually open the password manager, look for the password, copy+paste, and save the new entry. How can you be completely confident that this isn't an attacker?

In that rare case you just check the URL. Contact the company if it is a high value login. You can also verify by searching for the site and clicking through to see what their webpage offers as ground truth.

Re: That's not how 2FA works

#88
post #19

The Yubikey/WebAuthn comments are really ignorant and discouraging people from the best defense against this sort of attack that exists. First of all you can get WebAuthn devices for as little as $10 now. Second, there is no app to configure. You plug it in when it says register and tap it. Done. Third, if the WebAuthn device gets stolen the attacker presumably lacks a password. You can't use the device by itself. Al…

Disappointed but not surprised when reading this. To be really honest, I can't remember the last time I read something that criticized so called "techbros" and actually said something reasonable. As for the U2F devices, the idea of just leaving them in, the small yubikeys and all that, seem to just be a bad idea from the get-go.

You can leave them in, but you still have to tap/touch them for every authentication action (user interaction); the small YubiKey Nano included.

Re: That's not how 2FA works

#89
post #19

The Yubikey/WebAuthn comments are really ignorant and discouraging people from the best defense against this sort of attack that exists. First of all you can get WebAuthn devices for as little as $10 now. Second, there is no app to configure. You plug it in when it says register and tap it. Done. Third, if the WebAuthn device gets stolen the attacker presumably lacks a password. You can't use the device by itself. Al…

Disappointed but not surprised when reading this. To be really honest, I can't remember the last time I read something that criticized so called "techbros" and actually said something reasonable. As for the U2F devices, the idea of just leaving them in, the small yubikeys and all that, seem to just be a bad idea from the get-go.

What is your objection to just leaving a yubikey plugged in? It eliminates most of the ways an attacker could impersonate me besides literally stealing my laptop, which is a high bar. Most people are valuable enough targets to phish or infect with malware or something, but not to plan a computer heist.

Re: That's not how 2FA works

#90
post #3

Earlier quoted context omitted.

With an email link or a Yubikey it might, but with SMS or an Authenticator app it doesn't add any extra way for me to identify the site.

Email is not really a 2FA though if it can also be used to reset your password.

Interesting point. I hadn't thought about that. Helps that access to my email is 2FA, but it does make for a single point of failure.
Post reply on HN