Live data from Hacker News

Support for U2F security keys

blog.1password.com

11–20 of 164 posts

Re: Support for U2F security keys

#11
I have never used 1password.com.

Adding 2FA to it is great but I think the best security is likely still just to sync and use local apps for this data, to avoid being exposed to any JavaScript vulnerabilities or if 1password.com were ever hacked.

Re: Support for U2F security keys

#12

This looks awesome and I wish I could use it. Could you guys also consider bringing back the completely-offline mode that doesn't make my password manager depend on a 3rd party service? I'm prohibited by company policy from using my favorite password manager because of this.

You mean the licensed version? It never went away.

When you launch you'll be prompted to purchase. On the screens near the bottom there is a line of text about purchasing a license, go that route instead of signing up for the 1Password.com service.

Kyle

1Password

Re: Support for U2F security keys

#13
post #3

It appears via the screenshot that you can have multiple 2FA devices, which is great. I love my Yubikey in theory, but in practice I'm only using it for services where I can have a TOTP or SMS 2FA backup method, because I'm not convinced it will always work or be available. Even if having SMS 2FA enabled negates any security benefits of the Yubikey. Thus far it's just Dropbox and Gitlab that I use it for, since they'…

Correct, you can add several devices. You can have TOTP + U2F devices or just U2F devices or just TOTP.

It's as simple as clicking the button to add another, and walking through the steps. Just be sure to name them in such a way that you can tell them apart. I typically use the identifier on the key itself. It's usually printed somewhere opposite the USB contacts.

Kyle

1Password

Re: Support for U2F security keys

#14
post #9
post #7

Earlier quoted context omitted.

Which services that support U2F do not support multiple devices (that you care about)?

Last I checked, Twitter supports U2F, but only allows enrolling one key. edit: I guess the thread is referring to multiple fallbacks that aren't U2F, but even still, if you're relying solely on U2F it's good practice to have more than one key lest you lose it and get locked out.

Amazon/AWS only allows a single MFA device.

Re: Support for U2F security keys

#15
post #3

It appears via the screenshot that you can have multiple 2FA devices, which is great. I love my Yubikey in theory, but in practice I'm only using it for services where I can have a TOTP or SMS 2FA backup method, because I'm not convinced it will always work or be available. Even if having SMS 2FA enabled negates any security benefits of the Yubikey. Thus far it's just Dropbox and Gitlab that I use it for, since they'…

All the services that I have used with U2F support have supported multiple keys. Google, Gitlab, Github, and some others which I forget.

They have all worked with Yubico U2F keys and with the Google Titan keys. Pretty convenient way to have two factor authentication. I like the Yubikey 5 Nano as you can leave it plugged into a port in your laptop all the time.

Re: Support for U2F security keys

#16

Got a free YubiKey from Wired. Then I read that mobile is a pain, and that I really need two ... it's sat in my bag now for months, unused. I already use 2FA, and it works good enough - I'm not sold on how this will make my life better, especially on mobile.

The primary purpose of U2F/WebAuthn is to break phishing attacks. Code-based TOTP 2FA, the kind you're probably using now, is already adequate to the task of making sure you're not credential-stuffed.

Re: Support for U2F security keys

#17

Got a free YubiKey from Wired. Then I read that mobile is a pain, and that I really need two ... it's sat in my bag now for months, unused. I already use 2FA, and it works good enough - I'm not sold on how this will make my life better, especially on mobile.

I’m going to use both. TOTP most of the time, U2F in a safe at home in case I break/lose my phone

Re: Support for U2F security keys

#18
post #12

This looks awesome and I wish I could use it. Could you guys also consider bringing back the completely-offline mode that doesn't make my password manager depend on a 3rd party service? I'm prohibited by company policy from using my favorite password manager because of this.

You mean the licensed version? It never went away. When you launch you'll be prompted to purchase. On the screens near the bottom there is a line of text about purchasing a license, go that route instead of signing up for the 1Password.com service. Kyle 1Password

Interesting. If this is the case, I think you have a communications problem. I was under the impression that after 6.0, the only way to get a license was to have your older one grandfathered. I can't find any information about this on your website. All of the options on your product info pages other than "enterprise (email us for a quote)" show monthly subscriptions only.

Where can I see product info about the licensed version? Can you provide a link?

Re: Support for U2F security keys

#19
post #8
post #3

It appears via the screenshot that you can have multiple 2FA devices, which is great. I love my Yubikey in theory, but in practice I'm only using it for services where I can have a TOTP or SMS 2FA backup method, because I'm not convinced it will always work or be available. Even if having SMS 2FA enabled negates any security benefits of the Yubikey. Thus far it's just Dropbox and Gitlab that I use it for, since they'…

I have 3 yubikeys to avoid this problem

How do you manage keeping all the keys "synced" in terms of which services they are registered with.

I keep keys in separate locations for safety, but that makes adding all keys to a new account a big pain.

This hasn't been a big problem yet because there are so few services that support the keys, but I wonder how people would manage it if it became widespread.

Re: Support for U2F security keys

#20

I have never used 1password.com. Adding 2FA to it is great but I think the best security is likely still just to sync and use local apps for this data, to avoid being exposed to any JavaScript vulnerabilities or if 1password.com were ever hacked.

1Password has Wifi Sync option too.
Post reply on HN