Live data from Hacker News

Show HN: A virtual Yubikey device for 2FA/WebAuthN

github.com

141–143 of 143 posts

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#141
post #54
post #2

I can't figure out why I'd want a Yubikey. Every year or so I try to figure out if a 2fa device practically has sufficient support that using it would improve my security. The answer has always been no. No 2fa device has sufficient support that it could increase the security of my 1password account, which I use on Linux and Android. No 2fa device has sufficient support that it could be used to unlock the lockscreen o…

I use 1Password and 2 Yubikey. Both yubikeys are configured to enter the same impossible to memorize password on a press to unlock 1Password, hid mode is supported by every device with a USB ports. I also use them as an otp second factor when a site requires it. Finally, they are configured with a x509 certificate that I use as my ssh keys. I generate one key per devices that way the secret never leaves it and I requ…

You also risk locking yourself out of your life with a setup like that

Re: Show HN: A virtual Yubikey device for 2FA/WebAuthN

#143
post #112
post #65

Earlier quoted context omitted.

So if your device is compromised, the attacker could trick you into entering 2FA for some minor action while it actually is transferring all your funds. If your PC or smartphone is compromised nothing will prevent you from losing control of your accounts.

That's kinda problem of many 2FA systems, my bank's send me the reason for 2FA and amount + last few digits of account if it is money transactions.

Yes, that is what I was trying to point out. With Yubikey or other 2FA devices you can not see the transaction details of what are you signing unless the device has a screen so a screenless device does not protect much more than this virtual yubikey.
Post reply on HN