There's still one huge disadvantage with hardware-based FIDO U2F tokens: There's no good way to migrate from one to another. I've got three(!) Yubikeys of different generations on my keyring because I'm not sure whether I have enrolled the two newer ones to all the services I'm using.
Yubico launches its dual USB-C and Lightning two-factor security key
111–120 of 178 posts
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#112Earlier quoted context omitted.
Yeah, I'm annoyed by having to chose between NFC and USB-C. Apparently they're working on it, though: https://twitter.com/Yubico/status/1161003411501748224
https://solokeys.com/ also
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#113Re: Yubico launches its dual USB-C and Lightning two-factor security key
#114Re: Yubico launches its dual USB-C and Lightning two-factor security key
#115Earlier quoted context omitted.
Interesting point - it's essentially a long lived secret. Actually what would happen if [large_comapny] had their TOTP secret revealed? Would they be forced to invalidate everyones TOTP? They can't just disable it they would have to somehow authenticate you a third way....
> Actually what would happen if [large_comapny] had their TOTP secret revealed? Would they be forced to invalidate everyones TOTP? Yes. RSA got hacked for their SecurID information, so that the attackers could then turn around and get into Lockheed Martin: * https://gcn.com/articles/2011/06/07/rsa-confirms-tokens-used... * https://www.scmagazine.com/home/security-news/rsa-confirms-l... Among other things, LM makes th…
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#116> Security keys offer almost unbeatable security and can protect against a variety of threats, including nation-state attackers. Alright, I'm not a security expert, but I'm not completely illiterate to basic computer security. Anyone care to chime in how this is much more secure than a two-factor app? Sure there's the obvious, nobody can just copy the two-factor app off my phone with all the codes and have the same c…
Yubico has some FIPS certified devices[2], which means that they've presented a design that shows the device has mechanisms to prevent secrets from being extracted, and they're only using algorithms known by NIST not to leak secrets.
> Also pardon me if I confused two-factor as the Google Authenticator app.
Multi-factor authentication is about managing risk, and discussions about risk are naturally fuzzy and vague.
I'll try a concrete analogy; consider firearms safety.
Some typical rules[3]: 1. keep the weapon pointed down range at all times, 2. keep your finger out of the trigger well, 3. treat the weapon as loaded at all times.
Each rule is a factor, and to accidentally hurt someone you have to violate all the rules at once.
Multiple factors work best if they are orthogonal, that is, when a given action results in only breaching a single factor. That's why factors tend to be phrased as "something you know," "something you are," "something you have".
The authenticator app and a Yubikey are doing the exact same thing: they're establishing the "something you have" factor.
Since the two factors work when an attacker must both obtain the device and get your password, if your phone has both passwords and authenticator apps, the additional factors aren't minimizing that risk.
[1]: The automatic vendor lock-in makes it a great business model...
[2]: https://www.yubico.com/business/product/yubikey-fips
[3]: There are many more, but take a class on it rather than depend on the Internet.
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#117Earlier quoted context omitted.
So far it sounds like the next iPhone will still use lightning, so you should be safe using this Yubikey for a few years at least.
It would be deeply frustrating if Yubico were to spend years coming up with a 2FA product that works with iDevices, and then a few months later Apple were to throw out the interface that product depends on and thus instantly make it completely obsolete. (One would hope that Yubico and Apple have been in touch with each other at least the minimal amount that would be required to avoid such a fiasco. But given Apple's…
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#118The Yubikey website is vague, but it seems like the lightning end only works with a few apps (1Password, Brave, etc). What do I do if I want to sign in to anything else that needs 2FA? Do I still need a TOTP app?
From what I've heard from Yubico the next version of iOS is going to make it far easier to communicate with the device. Integrations will probably still need to be added by the app developers though to take full advantage.
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#119The Yubikey website is vague, but it seems like the lightning end only works with a few apps (1Password, Brave, etc). What do I do if I want to sign in to anything else that needs 2FA? Do I still need a TOTP app?
From what I've heard from Yubico the next version of iOS is going to make it far easier to communicate with the device. Integrations will probably still need to be added by the app developers though to take full advantage.
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#120Handy table comparing their 5-series options: * https://www.yubico.com/products/yubikey-hardware/compare-yub... Seems the main questions to ask yourself are: * is NFC desired? * do you need/want USB-A or USB-C? This product adds a Lightning option.
Is there no lightning to USB A adapter? Seems a bit wasteful to buy another key for a currently very limited ability in iOS.