With more interaction online moving to smartphones and tablets, what do we do instead of USB hardware keys like these?
Wearables with BTLE.
Strengthening 2-Step Verification with Security Key
21–30 of 150 posts
Re: Strengthening 2-Step Verification with Security Key
#22This seems to me to be a bit of a narrow market. At the upper end of secure machines, USB ports will be physically disabled. And if you're not hyper security conscious, you're not going to bother with a physical key. So with this, you need to be somewhat paranoid, but not totally paranoid.
Re: Strengthening 2-Step Verification with Security Key
#23Re: Strengthening 2-Step Verification with Security Key
#24Security Key does not work on browsers other than Chrome. Well that's a bummer. Doesn't mean it can't be useful in some settings, though.
> Security Key and Chrome incorporate the open Universal 2nd Factor (U2F) protocol from the FIDO Alliance, so other websites with account login systems can get FIDO U2F working in Chrome today. It’s our hope that other browsers will add FIDO U2F support, too.
Re: Strengthening 2-Step Verification with Security Key
#25How does the challenge get from the web browser out to the USB device? I've spent some time looking for a specification, but haven't managed to find the answer to this question.
Re: Strengthening 2-Step Verification with Security Key
#26Sounds like an interesting idea but isn't it a bit limited? I can only use it on a computer, not on mobile devices.
Re: Strengthening 2-Step Verification with Security Key
#27Security Key does not work on browsers other than Chrome. Well that's a bummer. Doesn't mean it can't be useful in some settings, though.
Re: Strengthening 2-Step Verification with Security Key
#28How does the challenge get from the web browser out to the USB device? I've spent some time looking for a specification, but haven't managed to find the answer to this question.
The device probably registers as a USB keyboard, and it "types out" the 2-factor code when you tap it.
Re: Strengthening 2-Step Verification with Security Key
#29How does the challenge get from the web browser out to the USB device? I've spent some time looking for a specification, but haven't managed to find the answer to this question.
Re: Strengthening 2-Step Verification with Security Key
#30This seems to me to be a bit of a narrow market. At the upper end of secure machines, USB ports will be physically disabled. And if you're not hyper security conscious, you're not going to bother with a physical key. So with this, you need to be somewhat paranoid, but not totally paranoid.
The reason that "upper end of secure machines" have disabled USB ports is because they are organization-owned machines that are issued to untrusted employees (often in organizations where all employees are untrusted in the relevant sense). But in the case of first-party machines (e.g., personally owned machines) where the user is similarly security-conscious, that factor doesn't exist. So, really, all you need to be is a security-conscious individual that uses your own computer for things where you have security concerns. (Or, as an organization, be one where the threat profile you concerned about addressing is more external than internal.)