Live data from Hacker News

Strengthening 2-Step Verification with Security Key

googleonlinesecurity.blogspot.com

41–50 of 150 posts

Re: Strengthening 2-Step Verification with Security Key

#41

Shame I have to pick EITHER 2-step or Security Key. My ideal would be to use Security Key to bypass 2-step on devices that supported it and then use 2-step elsewhere. For example, some public computers have the USB port literally glued shut, therefore Security Key won't work. In those cases I'll still have my phone with me and could bypass it via 2-step. Essentially I want to use the Security Key as a way to save me…

> Shame I have to pick EITHER 2-step or Security Key.

You don't. You must use 2-step to use Security Key.

> My ideal would be to use Security Key to bypass 2-step on devices that supported it and then use 2-step elsewhere.

That's exactly what happens when you use Security Key. FTFA: If you use 2-Step Verification, you can choose Security Key as your primary method [...] In general, you’ll still be able to use a verification code the way you normally do on any device that doesn’t support Security Key.

Re: Strengthening 2-Step Verification with Security Key

#42
post #25
post #23

How does the challenge get from the web browser out to the USB device? I've spent some time looking for a specification, but haven't managed to find the answer to this question.

The device probably registers as a USB keyboard, and it "types out" the 2-factor code when you tap it.

Right, but how does the challenge get to the device?

"Security Key is a physical USB second factor that only works after verifying the login site is truly a Google website, not a fake site pretending to be Google."

The specs say that a challenge is involved. The device must receive the challenge. "Typing out" keys isn't sufficient unless that typing can go the other way. And in the OS, there has to be support for Chrome to send data to such a device. Normal keyboard input is not sufficient for this. This is what I'm looking for clarity on.

Re: Strengthening 2-Step Verification with Security Key

#44
post #38
post #28

Earlier quoted context omitted.

[deleted]

No, it's not. It's using HID, but not by identifying itself as a keyboard.

The Yubikey website specifies that the device registers as a Keyboard, flash card, and flash reader when you plug it in. That said it isn't entirely clear if this new standard utilizes that or if that's merely provided as a fallback for older devices that don't support this new protocol.

Edit: After consulting the specification for this standard it does appear as if it uses the core USB specification to communicate with supported devices when using this protocol. There is also information stating that NFC, bluetooth and other transports will have specification provides later on but that they currently only have a spec for communication over USB. The takeaway appears to be that the Yubikey device can function as a 2FA over NFC or USB when in a sort of fallback mode that emulates a keyboard, but when used directly with this protocol can only support USB. It's possible there might be some driver shims that allow it to communicate over NFC while still appearing as a USB device to the browser, but that would of course require a custom driver be installed and most likely violates this standard in its current formulation.

Re: Strengthening 2-Step Verification with Security Key

#45

Shame I have to pick EITHER 2-step or Security Key. My ideal would be to use Security Key to bypass 2-step on devices that supported it and then use 2-step elsewhere. For example, some public computers have the USB port literally glued shut, therefore Security Key won't work. In those cases I'll still have my phone with me and could bypass it via 2-step. Essentially I want to use the Security Key as a way to save me…

Not sure about it, but this page [1] does say "In general, you’ll still be able to use a verification code the way you normally do on any device that doesn't support Security Key." Assuming you'd be able to tell it that it doesn't support it, rather than it just deciding based on hardware?

[1] https://support.google.com/accounts/answer/6103523

Re: Strengthening 2-Step Verification with Security Key

#47

Shame I have to pick EITHER 2-step or Security Key. My ideal would be to use Security Key to bypass 2-step on devices that supported it and then use 2-step elsewhere. For example, some public computers have the USB port literally glued shut, therefore Security Key won't work. In those cases I'll still have my phone with me and could bypass it via 2-step. Essentially I want to use the Security Key as a way to save me…

You don't have to pick one or the other. According to the FAQ [0] (linked from the blog post):

"In general, you’ll still be able to use a verification code the way you normally do on any device that doesn’t support Security Key."

[0] https://support.google.com/accounts/answer/6103523

Re: Strengthening 2-Step Verification with Security Key

#48
Would be good if next gen chromebooks have a bay on the bottom with a USB socket so you can leave one of these attached without it dangling off the side (and maybe permanently glued in by paranoid IT). Another trick might be NFC in the palmrests that can detect your watch . . .

Looks like a solid step in the right direction though.

Re: Strengthening 2-Step Verification with Security Key

#49

Would be good if next gen chromebooks have a bay on the bottom with a USB socket so you can leave one of these attached without it dangling off the side (and maybe permanently glued in by paranoid IT). Another trick might be NFC in the palmrests that can detect your watch . . . Looks like a solid step in the right direction though.

Yubikey's first offering that is U2F compatible is that bright blue USB key, but they have previously offered a USB key that is almost flush with the port, and the conductive contact is on the edge of it. I suspect they'll be updating that product to offer U2F soon, and it should be a better fit for what you are asking.

Re: Strengthening 2-Step Verification with Security Key

#50
post #42
post #25

Earlier quoted context omitted.

The device probably registers as a USB keyboard, and it "types out" the 2-factor code when you tap it.

Right, but how does the challenge get to the device? "Security Key is a physical USB second factor that only works after verifying the login site is truly a Google website, not a fake site pretending to be Google." The specs say that a challenge is involved. The device must receive the challenge. "Typing out" keys isn't sufficient unless that typing can go the other way. And in the OS, there has to be support for Chr…

[deleted]
Post reply on HN