Live data from Hacker News

Strengthening 2-Step Verification with Security Key

googleonlinesecurity.blogspot.com

101–110 of 150 posts

Re: Strengthening 2-Step Verification with Security Key

#101
post #91
post #61

Earlier quoted context omitted.

The insecurity relates the problem with allowing random usb devices to be plugged into a computer. Specifically, it points out that, even if you wipe an usb stick, you still can't trust that it's safe. The devices that Google is referring to should be inherently safe. If you don't trust the supplier of these devices then yes, that's an issue. But, in theory, you receive these from a trusted source. As long as the dev…

I have a Yubikey and it isn't read only. You can customize how it works with software they provide.

Setting parameters in the device is different than replacing the firmware. The attack requires replacing the firmware. As far as I know yubikeys have never been able to update firmware after they've left the factory. In the forums you will see yubico people offering to swap devices because of problems related to outdated firmware.

There was also a blog post by yubico confirming that the badusb attack is irrelevant on yubikeys. https://www.yubico.com/2014/08/yubikey-badusb/

I think the take away is that all the devices are read only except the Neo and the Device Firmware Upgrade (DFU) implementation on the Neo "requires the new firmware image to be signed by [yubico]. Yubico does not endorse nor support use of DFU for users"

The Neo also has javacard capability that lets you load applets. In the latest devices unless you purchase the developer editions, the javacard apps cannot be updated.* Older Neo's allowed you to build and load your own javacard apps.

* I'm not entirely sure about whether in the latest Neos the javacard apps can be updated to new official signed yubikey versions or whether the javacard apps cannot be updated at all...

Re: Strengthening 2-Step Verification with Security Key

#102
post #60
post #40

Earlier quoted context omitted.

Not sure how it will interact with this, but at least one of the compatible Yubikey devices that was mentioned also supports NFC specifically for use on mobile devices that lack USB ports.

As an addendum to this, after looking over the spec, it appears that the FIDO-U2F protocol currently only supports USB, but that support for NFC and bluetooth is planned in later versions of the specification. Presumably a firmware update sometime down the line would be sufficient to bring the Yubikey device up to date with the NFC standard and allow it to work over NFC in addition to the currently supported USB vers…

That would be quite awesome.

Re: Strengthening 2-Step Verification with Security Key

#104
post #58

EDIT: Looks like this is now working! Looks like there is a tiny UI bug -- make sure your account is correctly selected on the Security Token page if you have multiple accounts signed in. #userError Ouch, looks like a serious downside is that a given key can only be used with one Google account. Trying to add a U2F-compatible token to more than one Google account results in errors: "This Security Key is already regis…

I have the same security keys registered with three completely different google accounts (two completely unrelated domain accounts and one gmail account), so i'm not sure what's going on for you.

Re: Strengthening 2-Step Verification with Security Key

#105
post #66

Earlier quoted context omitted.

Thanks, this is useful. As a custom USB HID device then, I wonder if the OS has to get involved? Or is custom support in the application sufficient?

LOL "No need for ... client software..." ... Uses ... built-in support directly into the browser". So when did a browser stop being "client software" ? Never let the truth get in the way of a good advertising claim eh?

So when did a browser stop being "client software"?

Around the time Netscape relegated Windows to a bunch of device drivers?

Re: Strengthening 2-Step Verification with Security Key

#106
post #12

Security Key does not work on browsers other than Chrome. Well that's a bummer. Doesn't mean it can't be useful in some settings, though.

Also this though: > Security Key and Chrome incorporate the open Universal 2nd Factor (U2F) protocol from the FIDO Alliance, so other websites with account login systems can get FIDO U2F working in Chrome today. It’s our hope that other browsers will add FIDO U2F support, too.

If you share the same FIDO U2F key between services, does that mean that one service could spoof tokens for a different service?

e.g. foo gets compromised, so attackers can generate codes for google apps.

Re: Strengthening 2-Step Verification with Security Key

#107
post #60
post #40

Earlier quoted context omitted.

Not sure how it will interact with this, but at least one of the compatible Yubikey devices that was mentioned also supports NFC specifically for use on mobile devices that lack USB ports.

As an addendum to this, after looking over the spec, it appears that the FIDO-U2F protocol currently only supports USB, but that support for NFC and bluetooth is planned in later versions of the specification. Presumably a firmware update sometime down the line would be sufficient to bring the Yubikey device up to date with the NFC standard and allow it to work over NFC in addition to the currently supported USB vers…

Yubico doesn't allow firmware updates. They do, however, support the GlobalPlatform standard for uploading new JavaCard applets, and, if the NFC bindings were designed such that a JavaCard applet could implement it, then a U2F applet could be uploaded to an existing YKNeo.

Re: Strengthening 2-Step Verification with Security Key

#108
post #91
post #61

Earlier quoted context omitted.

The insecurity relates the problem with allowing random usb devices to be plugged into a computer. Specifically, it points out that, even if you wipe an usb stick, you still can't trust that it's safe. The devices that Google is referring to should be inherently safe. If you don't trust the supplier of these devices then yes, that's an issue. But, in theory, you receive these from a trusted source. As long as the dev…

I have a Yubikey and it isn't read only. You can customize how it works with software they provide.

The important part is you can't read your private key out, nor update the firmware to something that allows you to read the private key out. The customization you can do is unrelated.

Re: Strengthening 2-Step Verification with Security Key

#109

Cool, but I will continue using the Google Authenticator app. Google is not the only thing that requires 2FA, so do numerous other sites, and GA app is the most widely supported and the least pain in the behind. I don't see a point in plugging my entire keychain (the physical keychain, with my car keys) into my laptop every time I want to log into GMail, much less carrying around 10+ different USB tokens. Now, a NFC-…

Don't keep it on the same keychain as your car keys. I don't–that would be terribly impractical. Instead, it lives in my laptop slipcase.

Even better, get the nano version and leave it in your USB slot permanently: http://www.amazon.com/dp/B00O8ST7MM

Re: Strengthening 2-Step Verification with Security Key

#110
post #96

Good luck plugging a USB key into your iPad, or letting your security-sensitive workplace let you plug arbitrary USB keys into your workstation, or convincing your bank that you really did not send your entire balance to Nigeria, even though you signed that transaction with a tap, etc etc... Remember Mt.Gox? That's Yubico's most public failure so far :-) Strong authentication needs to be out-of-band, and support tran…

Can you please explain or give sources on why Mt.Gox is Yubi's most public failure? I started using Yubikey some months ago and this is news to me, so any info would be appreciated.

It had nothing to do with Yubikey. Mt.Gox implemented time based 2FA (think google authenticator) via Yubikey. The fact that Mt.Gox subsequently imploded had nothing to do with Yubikey and seems almost entirely to be based around a poor implementation with regards to handling bitcoin transactions combined with insider fraud.

Public disclosure, I lost ~$700 to Mt.Gox, a tiny amount compared to some, mostly I was just trying to cash out a couple coins at the height of the bubble. I'm not terribly upset over it, although it would have been nice to see that $700 in my account, or at least get my 2 coins back.

Post reply on HN