Live data from Hacker News

Using a Yubikey as a touchless, magic unlock key for Linux

kliu.io

11–20 of 74 posts

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#11

Earlier quoted context omitted.

> If the author hasn't figured out you can assign a PIN to the keys you store on the Yubi, then I don't see why I should waste my time reading their rambling blog post. Try being a little nicer. If you feel that the blog post is a waste of your time, here's a revolutionary idea – don't say anything? There are 29 other posts on the front page, maybe one of those other ones will be worth your time. As it is, the UX of…

I’m someone that often reads the comments before reading the article, so it’s helpful to know what people think is blog spam and what is actually worth reading.

Understood.

I'm making the claim that the OP's comment is both derogatory ("rambling", "waste of my time") and not relevant to the solution described in the article. Therefore, if anything, the comment is more deserving of being labeled spam than the article itself.

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#12
Some time there was a similar tool that locked the computer via bluetooth if you walked away from the desk with your phone. It didn't unlock it which is fine, but it seems a better way to lock a computer if you forget rather than a timed screensaver after x minutes which leaves the computer vulnerable until then. (Mostly just from colleagues changing your wallpaper, or autocorrect...)

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#13

Earlier quoted context omitted.

> If the author hasn't figured out you can assign a PIN to the keys you store on the Yubi, then I don't see why I should waste my time reading their rambling blog post. Try being a little nicer. If you feel that the blog post is a waste of your time, here's a revolutionary idea – don't say anything? There are 29 other posts on the front page, maybe one of those other ones will be worth your time. As it is, the UX of…

I’m someone that often reads the comments before reading the article, so it’s helpful to know what people think is blog spam and what is actually worth reading.

Seconded. I think one of Hackernews’ biggest value-adds versus say Oreilly is the eagerness with which the commenters on this site will rip apart bad ideas/articles.

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#14

I stopped reading at the first paragraph: "At that point, anyone can take the key and use it for 2-factor authentication/SSH/GPG signing, so it’s not much better than just using a normal password.". If the author hasn't figured out you can assign a PIN to the keys you store on the Yubi, then I don't see why I should waste my time reading their rambling blog post. Good luck taking my Yubikey and trying to SSH to my ki…

Author of the post here - you have a good point with regard to SSH/GPG. (I do have a PIN on my keys.) I was targeting more the U2F standpoint - as in if you're using it for 2FA, it's obviously no better than a password if someone else can just press the little yellow button :)

Thanks for reading, though, and for commenting!

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#15

I stopped reading at the first paragraph: "At that point, anyone can take the key and use it for 2-factor authentication/SSH/GPG signing, so it’s not much better than just using a normal password.". If the author hasn't figured out you can assign a PIN to the keys you store on the Yubi, then I don't see why I should waste my time reading their rambling blog post. Good luck taking my Yubikey and trying to SSH to my ki…

> If the author hasn't figured out you can assign a PIN to the keys you store on the Yubi, then I don't see why I should waste my time reading their rambling blog post. Try being a little nicer. If you feel that the blog post is a waste of your time, here's a revolutionary idea – don't say anything? There are 29 other posts on the front page, maybe one of those other ones will be worth your time. As it is, the UX of…

The point is the author of the blog is spreading FUD by saying "you can't leave your Yubikey unattended because anybody can take it and use it to SSH without your consent".

That is a falsehood and deserves to be called out.

I don't mind "revolutionary ideas", but don't use your platform to spread FUD.

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#16

Earlier quoted context omitted.

I’m someone that often reads the comments before reading the article, so it’s helpful to know what people think is blog spam and what is actually worth reading.

Seconded. I think one of Hackernews’ biggest value-adds versus say Oreilly is the eagerness with which the commenters on this site will rip apart bad ideas/articles.

I agree, but also you can be critical without being an asshat.

It's better to comment from a perspective of "I bet you didn't know this" than "Ha, you're an idiot"

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#17

I stopped reading at the first paragraph: "At that point, anyone can take the key and use it for 2-factor authentication/SSH/GPG signing, so it’s not much better than just using a normal password.". If the author hasn't figured out you can assign a PIN to the keys you store on the Yubi, then I don't see why I should waste my time reading their rambling blog post. Good luck taking my Yubikey and trying to SSH to my ki…

Author of the post here - you have a good point with regard to SSH/GPG. (I do have a PIN on my keys.) I was targeting more the U2F standpoint - as in if you're using it for 2FA, it's obviously no better than a password if someone else can just press the little yellow button :) Thanks for reading, though, and for commenting!

No hard feelings @Pneumaticat. ;)

Most places where I use the FIDO feature of Yubi (e.g. Github), you still need to provide username and password. So an abandoned Yubi is still of limited use assuming your password is stored securely.

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#18

Earlier quoted context omitted.

Author of the post here - you have a good point with regard to SSH/GPG. (I do have a PIN on my keys.) I was targeting more the U2F standpoint - as in if you're using it for 2FA, it's obviously no better than a password if someone else can just press the little yellow button :) Thanks for reading, though, and for commenting!

No hard feelings @Pneumaticat. ;) Most places where I use the FIDO feature of Yubi (e.g. Github), you still need to provide username and password. So an abandoned Yubi is still of limited use assuming your password is stored securely.

Yeah - here, I'll add a slight edit to the post to explain it in more detail and clear up any confusion.

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#19
Sounds good, but I'd really want to use a PIN with that. Otherwise anyone can take my key and walk up to the computer and unlock it.

I wonder if there is something like pam_piv? I use PIV already for Mac & Windows... Suppose I should look for it myself :)

Post reply on HN