Live data from Hacker News

Show HN: A virtual Yubikey device for 2FA/WebAuthN

github.com

1–10 of 143 posts

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#2
I can't figure out why I'd want a Yubikey.

Every year or so I try to figure out if a 2fa device practically has sufficient support that using it would improve my security. The answer has always been no.

No 2fa device has sufficient support that it could increase the security of my 1password account, which I use on Linux and Android. No 2fa device has sufficient support that it could be used to unlock the lockscreen of any of my devices either.

Edit: There is a way to use a Yubikey to decrypt Linux full-disk encryption. It relies on an abandoned personal GitHub project. Sounds fun, but not sufficiently secure it's worth spending more than $100 to allegedly improve my security with it.

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#4
post #2

I can't figure out why I'd want a Yubikey. Every year or so I try to figure out if a 2fa device practically has sufficient support that using it would improve my security. The answer has always been no. No 2fa device has sufficient support that it could increase the security of my 1password account, which I use on Linux and Android. No 2fa device has sufficient support that it could be used to unlock the lockscreen o…

I think a huge benefit of 2fa, one of the main purposes of it, was for securing accounts with weak passwords. Back in the days before password managers etc. I think these days password managers actually deprecate the need for 2fa

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#5
post #3

Fun demo but who is this really for? Is there a requirement for these devices anywhere aside from corporate security?

Personally, I prefer the "approval" process of YubiKey/U2F devices over having to enter a code, but I also dislike having to have a hardware device on me at all times. Also, with WebAuthN and passwordless login, YubiKeys are now able to be used to authenticate people, so I figure it would be nice to have a software solution for that.

Granted, this is still just a demo, so it's a long way off from something somebody would regularly use.

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#6
post #2

I can't figure out why I'd want a Yubikey. Every year or so I try to figure out if a 2fa device practically has sufficient support that using it would improve my security. The answer has always been no. No 2fa device has sufficient support that it could increase the security of my 1password account, which I use on Linux and Android. No 2fa device has sufficient support that it could be used to unlock the lockscreen o…

Can you define what do you mean by sufficient support?

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#7
post #3

Fun demo but who is this really for? Is there a requirement for these devices anywhere aside from corporate security?

This is primarily of use to people who want to disregard hardware authenticator requirements imposed by third parties without their consent.

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#8
post #4
post #2

I can't figure out why I'd want a Yubikey. Every year or so I try to figure out if a 2fa device practically has sufficient support that using it would improve my security. The answer has always been no. No 2fa device has sufficient support that it could increase the security of my 1password account, which I use on Linux and Android. No 2fa device has sufficient support that it could be used to unlock the lockscreen o…

I think a huge benefit of 2fa, one of the main purposes of it, was for securing accounts with weak passwords. Back in the days before password managers etc. I think these days password managers actually deprecate the need for 2fa

Every now and then you hear about a leak at some company that was storing passwords in clear text. Thanks to password managers this only affects that one site, but it still makes me thankful for 2FA.

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#10
post #3

Fun demo but who is this really for? Is there a requirement for these devices anywhere aside from corporate security?

> Fun demo but who is this really for?

Would being able to create virtual devices like this be more useful for testing authentication flows, compared to having physical test devices?

Post reply on HN