So, we recently had a bunch of articles coming out on "the fundamental insecurity of USB" [1]. How does that jive with a USB-based security key? Can't this be "flashed" like any other USB device? [1]: https://www.schneier.com/blog/archives/2014/07/the_fundament...
Strengthening 2-Step Verification with Security Key
51–60 of 150 posts
Re: Strengthening 2-Step Verification with Security Key
#52Re: Strengthening 2-Step Verification with Security Key
#53Earlier quoted context omitted.
Probably a similar device but with some sort of low-power NFC transponder rather than a physical connection.
I've never used it but, https://www.yubico.com/products/yubikey-hardware/yubikey-neo... seems to fit the bill.
I ended up just grabbing the clipboard app that yubikey puts out.
I tried using the static password feature by using it as part of my master password in 1password but the newer versions of 1password block using the clipboard in android (with good reason). It would be pretty awesome if password-managers added support for it.
Re: Strengthening 2-Step Verification with Security Key
#54This seems to me to be a bit of a narrow market. At the upper end of secure machines, USB ports will be physically disabled. And if you're not hyper security conscious, you're not going to bother with a physical key. So with this, you need to be somewhat paranoid, but not totally paranoid.
Re: Strengthening 2-Step Verification with Security Key
#55I don't get this, what about malware pretending to be a browser? Is there a protection against this in protocol
Re: Strengthening 2-Step Verification with Security Key
#56Would be good if next gen chromebooks have a bay on the bottom with a USB socket so you can leave one of these attached without it dangling off the side (and maybe permanently glued in by paranoid IT). Another trick might be NFC in the palmrests that can detect your watch . . . Looks like a solid step in the right direction though.
Re: Strengthening 2-Step Verification with Security Key
#57So, we recently had a bunch of articles coming out on "the fundamental insecurity of USB" [1]. How does that jive with a USB-based security key? Can't this be "flashed" like any other USB device? [1]: https://www.schneier.com/blog/archives/2014/07/the_fundament...
Meaning that theoretically someone could steal your key, alter the firmware, turn it into a virtual hub and attach virtual keyboards/USB sticks which do nasty things.
However the same can be said for any electrical device you carry. If you carry your laptop through a US border they can seize it for almost no reason, and attach things to the PCI bus directly internally (see the NSA's foreign intelligence catalogue for numerous examples).
The USB security issues are just fun ones to exploit (relatively easy, with great results). No firmware is REALLY verifiable (e.g. baseband, CPU microcode, BIOS/uEFI, et al).
Ultimately it boils down to physical security of your electronics and buying anonymously (so devices cannot be intercepted before they're delivered to you).
Re: Strengthening 2-Step Verification with Security Key
#58Ouch, looks like a serious downside is that a given key can only be used with one Google account.
Trying to add a U2F-compatible token to more than one Google account results in errors: "This Security Key is already registered. Use a key that is not registered yet and try again."
Re: Strengthening 2-Step Verification with Security Key
#59Re: Strengthening 2-Step Verification with Security Key
#60Not much of an improvement over 2FA using my phone because the times when I really need it to be easy is when I'm browsing on my phone. Since this is USB I can't use it on my phone. When I'm on my laptop I just pull out my phone and type in a short code and be done with it.
Not sure how it will interact with this, but at least one of the compatible Yubikey devices that was mentioned also supports NFC specifically for use on mobile devices that lack USB ports.