Live data from Hacker News

Support for U2F security keys

blog.1password.com

101–110 of 164 posts

Re: Support for U2F security keys

#101

Earlier quoted context omitted.

1Password has Wifi Sync option too.

Yep! 1password is great. I do use their cloud sync service with all the apps, I just don’t ever use the website or the browser extensions to limit my exposure.

Note that the browser extension actually does limit your exposure quite a bit. You make trade offs here.

For instance, if you aren't using the browser extensions, how are you getting your password to the browser to sign in? Copying and pasting? It's possible for any app on your system to read the clipboard.

Drag and drop should be a better alternative there, as we now support that in 1Password 7.

The extension though uses either Safari App Extension (for Safari, obviously) or Native Messaging Host (Firefox and Chrome browsers) and aren't susceptible to clipboard type snooping.

The browser extensions also only present items that match the website you're on. This helps a lot in phishing attempts.

So, yea, you could not use the browser extensions but you're going to have to trust that YOU always do the right thing.

Note again that 1Password does not "auto fill" like other password managers, where simply visiting the site fills the data in. You always have to explicitly ask 1Password to fill into the page.

Just some insight anyway.

Kyle

1Password

Re: Support for U2F security keys

#102

I'm seeing several links to different physical keys in the comments. Is there somewhere/someone that verifies these keys? Like a 3rd party testing/standards body? I've always had it drilled into me that doing crypto yourself is fraught with peril. It seems that doing hardware would be doubly dangerous. I'd want more verification that the implementation is correct and "strong".

There are FIPS versions of Yubi Keys:

https://www.yubico.com/products/yubikey-fips/

These are validated by NIST (National Institute of Standards):

https://csrc.nist.gov/Projects/Cryptographic-Module-Validati...

Re: Support for U2F security keys

#103
post #25

I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?

Either the USB-A dongle or the USB-C one should work in all of these cases with an additional dongle (sigh).

By the way: I recommend getting the larger keys, not the nanos. These nanos look cute, but especially the newer ones are intended to be fixed to one device permanently, which in my opinion is both inconvenient and not the intended usage.

I wonder if iPad apps will start supporting Yubikeys — especially with the new iPad pros and their USB-C port it seems natural.

Ideally, I'd love to see Blink integrate ssh-agent, gpg-agent and its card support, which would let me use my existing (excellent) setup for using GPG keys stored on a Yubikey for ssh (see https://github.com/drduh/YubiKey-Guide for a great writeup of this approach).

Re: Support for U2F security keys

#104
post #48
post #25

I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?

Usually you just use multiple keys - one USB-C in the MacBook, one tiny USB-A in the laptop and the built-in Titan key in the Pixel phone. You don't remove them.

Aren't you effectively removing the second factor by keeping it permanently attached to each of your devices?

Re: Support for U2F security keys

#105

Got a free YubiKey from Wired. Then I read that mobile is a pain, and that I really need two ... it's sat in my bag now for months, unused. I already use 2FA, and it works good enough - I'm not sold on how this will make my life better, especially on mobile.

Why not use both? Most places that support 2FA support both TOTP (so Authy or Google Authenticator) and/or U2F/Webauthn. So, on mobile you can copy the authenticator codes, and on your computer you don't have to, as you can use the plugged in key.

Re: Support for U2F security keys

#106
post #95
post #64

I switched recently to Bitwarden. 1Passwords pricing/subscription changes was the the push I needed. Bitwarden has been fantastic, I highly recommend it. https://bitwarden.com

$2.99 per month is too steep of a price to pay for your personal security? Really? I'd dump my Spotify/Apple Music/Netflix/whatever in a heartbeat, if I had to choose between paid subscriptions in my life

$3 per month can be a lot of money, depending on where you live and your financial situation.

Bitwarden is free as in a beer and free as in speech. Only if you want the 2FA features you need a subscription.

Then Bitwarden costs 10 USD per year. That's approx as much as 1Password asks for 3 months. Ie. Bitwarden is almost 4 times as cheap.

For that price you get a very good program with an open source frontend, and an open source backend (third party, in Ruby).

And Lastpass, after they were acquired by LogMeIn, has the balls to go from 12 USD/year to 24 USD/year. Without any additional features whatsoever a 100% price increase? That's why I went shopping. And I ended up at Bitwarden.

Re: Support for U2F security keys

#107
post #104
post #48

Earlier quoted context omitted.

Usually you just use multiple keys - one USB-C in the MacBook, one tiny USB-A in the laptop and the built-in Titan key in the Pixel phone. You don't remove them.

Aren't you effectively removing the second factor by keeping it permanently attached to each of your devices?

Not unless your attacker has physical access to the machine. You still have to touch the device to activate it each time.

This still mitigates the most common MITM-type attacks:

1. Attacker instigates login via fake portal.

2. Attacker fools you in to entering your 6-digit OTP.

3. Attacker intercepts your valid OTP, combines with your stolen password, logs in to real site.

This doesn’t work with a YubiKey or the equivalent because of the back-and-forward cryptographic signing. The request has to come from the website you’re logging in to, which it doesn’t in this scenario. It’s the weakness of part 2 above which we avoid here.

Re: Support for U2F security keys

#108
post #104
post #48

Earlier quoted context omitted.

Usually you just use multiple keys - one USB-C in the MacBook, one tiny USB-A in the laptop and the built-in Titan key in the Pixel phone. You don't remove them.

Aren't you effectively removing the second factor by keeping it permanently attached to each of your devices?

Not really, because an attacker still needs physical access to the device. It still protects from someone with your password getting into the account (unless they have your laptop)

Re: Support for U2F security keys

#109
post #25

I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?

The new Yubikey's with NFC support work on my 2 year old iPhone already.

Re: Support for U2F security keys

#110

Earlier quoted context omitted.

A bluetooth capable U2F device like the Titan.

https://solokeys.com are an option as well if you like open hardware. https://github.com/solokeys/solo I think the NFC ones are shipping after they worked out some kinks.

Just got mine last week (Solo, Solo Tap, and the DigiPass SecureClick). All work great for their respective uses.
Post reply on HN