Live data from Hacker News

The Yubikey Is the Digital Seatbelt We Need

zagaja.com

11–20 of 73 posts

Re: The Yubikey Is the Digital Seatbelt We Need

#11
Yubikey will never prevent your data from being leaked. They didn’t crack your password.

But a random, unique password prevents further harm. They can’t get data from another site just because they hacked this one.

Have random, unique passwords. Use a password manager. Done.

Re: The Yubikey Is the Digital Seatbelt We Need

#12
post #9

Earlier quoted context omitted.

The banks used to hand out key response generation devices for that. No interface at all but the buttons. There even was a paper version where you scratched to get the key. Like, it was way better.

In the EU these hardware keyfobs are now forbidden for banking because they are considered less secure than app-based 2FA. The reason is that an app-based confirmation gives you the opportunity to review the transaction you are confirming; they can display "Are you sure you want to send 19.99 € to website.com with payment description 'subscription'?".

This is false.

I use a hardware thingy that I put my Dutch bank card into that generates numbers for logins and purchases. I have the option of using an app or the hardware card reader.

I use a one time generating password hardware keyfob to login to the Dutch Belastingdienst. They require it and I don't think there is an app I can use for this purpose.

Re: The Yubikey Is the Digital Seatbelt We Need

#13
post #9

Earlier quoted context omitted.

In the EU these hardware keyfobs are now forbidden for banking because they are considered less secure than app-based 2FA. The reason is that an app-based confirmation gives you the opportunity to review the transaction you are confirming; they can display "Are you sure you want to send 19.99 € to website.com with payment description 'subscription'?".

This is false. I use a hardware thingy that I put my Dutch bank card into that generates numbers for logins and purchases. I have the option of using an app or the hardware card reader. I use a one time generating password hardware keyfob to login to the Dutch Belastingdienst. They require it and I don't think there is an app I can use for this purpose.

All Dutch Banks are moving customers to their apps now.

Re: The Yubikey Is the Digital Seatbelt We Need

#14
post #2

No, it's not. We need less shoddy practices to develop software, e.g. mandatory 4-eyes process for security-critical changes, thread modelling, and maybe more Hardware Security Modules that encrypt critical information. And if you need a second factor, I'm sure any smartphone-based TOTP will do. People already guard their smartphone well. No extra key fob needed.

I have a yubikey. It's okay but I don't take it with me. When I'm out I use my phone with a MFA app, and would never tie my MFA to a hardware dongle that is likely not to be on my person when I need it.

Re: The Yubikey Is the Digital Seatbelt We Need

#16
post #2

No, it's not. We need less shoddy practices to develop software, e.g. mandatory 4-eyes process for security-critical changes, thread modelling, and maybe more Hardware Security Modules that encrypt critical information. And if you need a second factor, I'm sure any smartphone-based TOTP will do. People already guard their smartphone well. No extra key fob needed.

... Until you drop your phone and it breaks. And now you can't set up a new phone because you need to tap the notification sent to your old (now broken) phone in order to set up your new phone.

I've already had this happen, which is why I use hardware keys now, and a backup phone.

Re: The Yubikey Is the Digital Seatbelt We Need

#18
post #11

Yubikey will never prevent your data from being leaked. They didn’t crack your password. But a random, unique password prevents further harm. They can’t get data from another site just because they hacked this one. Have random, unique passwords. Use a password manager. Done.

I use my yubikey to lock my keepass database

Re: The Yubikey Is the Digital Seatbelt We Need

#19
post #2

No, it's not. We need less shoddy practices to develop software, e.g. mandatory 4-eyes process for security-critical changes, thread modelling, and maybe more Hardware Security Modules that encrypt critical information. And if you need a second factor, I'm sure any smartphone-based TOTP will do. People already guard their smartphone well. No extra key fob needed.

... Until you drop your phone and it breaks. And now you can't set up a new phone because you need to tap the notification sent to your old (now broken) phone in order to set up your new phone. I've already had this happen, which is why I use hardware keys now, and a backup phone.

Do you mean, you don't print these rescue codes which every 2FA thing keeps nagging you about? You don't have a printout in your wallet, or in your folder with important papers? Not even as a secure not in your password manager?..

Re: The Yubikey Is the Digital Seatbelt We Need

#20
post #15

Nope. It’s an add-on, but you can lose them. I am a bit flabbergasted that corporates are now handing them out like candy, but only one to a user. And if they lose them, they can’t even log in to request another.

I don't know which company you are talking about, but every company I've worked at always had a two Yubikey policy.
Post reply on HN