Live data from Hacker News

Strengthening 2-Step Verification with Security Key

googleonlinesecurity.blogspot.com

61–70 of 150 posts

Re: Strengthening 2-Step Verification with Security Key

#61
post #43

So, we recently had a bunch of articles coming out on "the fundamental insecurity of USB" [1]. How does that jive with a USB-based security key? Can't this be "flashed" like any other USB device? [1]: https://www.schneier.com/blog/archives/2014/07/the_fundament...

The insecurity relates the problem with allowing random usb devices to be plugged into a computer. Specifically, it points out that, even if you wipe an usb stick, you still can't trust that it's safe.

The devices that Google is referring to should be inherently safe. If you don't trust the supplier of these devices then yes, that's an issue. But, in theory, you receive these from a trusted source. As long as the device doesn't leave your possession, you're ok.

Edit: I should add that I didn't quite summarize the vulnerability correctly. If you plug a trusted USB device into an untrusted computer, you also have the potential for attack. If the USB device can be made writable, the computer can infect the USB device, propagating malware forward. I _assume_ that these security keys are made read-only before they leave factory, but vulnerabilities can be found in the darnedest of places!

Re: Strengthening 2-Step Verification with Security Key

#62
post #44
post #38

Earlier quoted context omitted.

No, it's not. It's using HID, but not by identifying itself as a keyboard.

The Yubikey website specifies that the device registers as a Keyboard, flash card, and flash reader when you plug it in. That said it isn't entirely clear if this new standard utilizes that or if that's merely provided as a fallback for older devices that don't support this new protocol. Edit: After consulting the specification for this standard it does appear as if it uses the core USB specification to communicate w…

  The Yubikey website specifies that the device registers as 
  a Keyboard, flash card, and flash reader when you plug it 
  in.
Looking at [1] it seems they make a range of products; some of their products implement multiple standards, as well as multiple USB devices. The "Premium NEO" emulates a keyboard to provide OATH HOTP, emulates a smart card reader to support PIV, and emulates a "FIDO U2F HID device" to support FIDO.

On the other hand, their "FIDO U2F Special SECURITY KEY", which only supports FIDO, does not emulate a keyboard or smart card reader - it only supports "FIDO U2F HID device"

So presumably FIDO relies on special browser support to talk to the physical hardware, and implements HID but doesn't emulate a keyboard.

[1] https://www.yubico.com/products/yubikey-hardware/

Re: Strengthening 2-Step Verification with Security Key

#63

Would be good if next gen chromebooks have a bay on the bottom with a USB socket so you can leave one of these attached without it dangling off the side (and maybe permanently glued in by paranoid IT). Another trick might be NFC in the palmrests that can detect your watch . . . Looks like a solid step in the right direction though.

Yubikey's first offering that is U2F compatible is that bright blue USB key, but they have previously offered a USB key that is almost flush with the port, and the conductive contact is on the edge of it. I suspect they'll be updating that product to offer U2F soon, and it should be a better fit for what you are asking.

The (expensive) Yubikey Neo Nano already supports U2F in the 'micro key' form-factor:

http://www.amazon.com/Yubico-Y-110-YubiKey-NEO-n/dp/B00O8ST7...

Hopefully they'll come out with a cheap U2F only nano-key soon.

Re: Strengthening 2-Step Verification with Security Key

#64

Would be good if next gen chromebooks have a bay on the bottom with a USB socket so you can leave one of these attached without it dangling off the side (and maybe permanently glued in by paranoid IT). Another trick might be NFC in the palmrests that can detect your watch . . . Looks like a solid step in the right direction though.

[deleted]

Re: Strengthening 2-Step Verification with Security Key

#65

Would be good if next gen chromebooks have a bay on the bottom with a USB socket so you can leave one of these attached without it dangling off the side (and maybe permanently glued in by paranoid IT). Another trick might be NFC in the palmrests that can detect your watch . . . Looks like a solid step in the right direction though.

Yubikey's first offering that is U2F compatible is that bright blue USB key, but they have previously offered a USB key that is almost flush with the port, and the conductive contact is on the edge of it. I suspect they'll be updating that product to offer U2F soon, and it should be a better fit for what you are asking.

They already have with the neo-n:

https://www.yubico.com/products/yubikey-hardware/

It does cost a bit more than the U2F-only version, however.

Re: Strengthening 2-Step Verification with Security Key

#66
post #44

Earlier quoted context omitted.

The Yubikey website specifies that the device registers as a Keyboard, flash card, and flash reader when you plug it in. That said it isn't entirely clear if this new standard utilizes that or if that's merely provided as a fallback for older devices that don't support this new protocol. Edit: After consulting the specification for this standard it does appear as if it uses the core USB specification to communicate w…

The Yubikey website specifies that the device registers as a Keyboard, flash card, and flash reader when you plug it in. Looking at [1] it seems they make a range of products; some of their products implement multiple standards, as well as multiple USB devices. The "Premium NEO" emulates a keyboard to provide OATH HOTP, emulates a smart card reader to support PIV, and emulates a "FIDO U2F HID device" to support FIDO.…

Thanks, this is useful.

As a custom USB HID device then, I wonder if the OS has to get involved? Or is custom support in the application sufficient?

Re: Strengthening 2-Step Verification with Security Key

#67
post #58

EDIT: Looks like this is now working! Looks like there is a tiny UI bug -- make sure your account is correctly selected on the Security Token page if you have multiple accounts signed in. #userError Ouch, looks like a serious downside is that a given key can only be used with one Google account. Trying to add a U2F-compatible token to more than one Google account results in errors: "This Security Key is already regis…

I just looked at the specification for this, it looks like a Google-specific limitation. There's no reason why a single site couldn't support the same U2F for multiple accounts.

In fact in Google's presentation they advertise a husband and wife using the same exact token for both of their accounts [0].

[0] https://sites.google.com/site/oauthgoog/gnubby

Re: Strengthening 2-Step Verification with Security Key

#68

Would be good if next gen chromebooks have a bay on the bottom with a USB socket so you can leave one of these attached without it dangling off the side (and maybe permanently glued in by paranoid IT). Another trick might be NFC in the palmrests that can detect your watch . . . Looks like a solid step in the right direction though.

The next release of ChromeOS will include nearby/proximity unlock features integrated with Android L, which they're calling "Easy Unlock".

There are a few somewhat-spammy blog summaries, e.g. http://www.omgchrome.com/chrome-os-smartphone-easy-unlock-fe...

Re: Strengthening 2-Step Verification with Security Key

#69
Cool, but I will continue using the Google Authenticator app. Google is not the only thing that requires 2FA, so do numerous other sites, and GA app is the most widely supported and the least pain in the behind. I don't see a point in plugging my entire keychain (the physical keychain, with my car keys) into my laptop every time I want to log into GMail, much less carrying around 10+ different USB tokens.

Now, a NFC-based token where I don't have to type anything in, or an iWatch/FitBit/whatever type wearable as a token would be pretty cool. Or even better: a universal library/service that abstracts which token I use. That way I can have multiple tokens for different situations.

Re: Strengthening 2-Step Verification with Security Key

#70
post #52

My worry about using my phone as the second factor is that my phone is attractive to thieves. I would personally prefer to carry around a keyring with many fobs on it.

It seems a bit cheesy, but I just put a lock screen on my phone. I figure if anyone steals it, they're unlikely to have the chops to bypass it without wiping the phone (I assume that's possible with adb at least). That combined with Google's remote wipe functionality and I'm pretty comfortable with the theft scenario.
Post reply on HN