Live data from Hacker News

How to Yubikey

debugging.works

111–120 of 186 posts

Re: How to Yubikey

#111
post #98
post #5

Reminder: Yubico doesn't have a monopoly on security keys. Make sure your software/tutorials support the open-source alternatives like OnlyKey and NitroKey.

do any other keys have feature sets on par with yubikeys? last i checked they were ahead by a mile, the others i looked at were just fido2 keys

so far, Yubikeys are the only ones I've found that support both FIDO2 / WebAuthn as well as GPG smart card functionality for use with pass(1).

they also support ed25519 FIDO SSH keys, whereas all the cheapo FIDO keys I've tested only support ecdsa-nistp256, but that's a relatively minor difference.

Nitrokey 3 claims that GPG smart card support is planned in an upcoming firmware update. once that's released I may bite the bullet on shipping costs and order one. 55€ shipping to the US for a 49€ key is cost-prohibitive for the most part.

Re: How to Yubikey

#112
post #108

Earlier quoted context omitted.

Ah, sorry for misunderstanding. BTW, that's a pretty cool project embedding a Solo 2 into the laptop. Shame you're now stuck with the Framework, but it's awesome that kind of project is even possible. I still prefer using a regular smartcard, since some (many?) laptops have built-in readers. And I miss PCMCIA slots, which were a perfect fit for smartcard readers, until they took it away from us. :(

Oh I'm not stuck, it's a removable port, I can just take the key out whenever. I think USB-C is more flexible than PCMCIA, especially with the Framework's module bays.

Well, you're functionally stuck with Framework, unless you want to go back to using the security key in the traditional way. I have the same issue with ThinkPads because of the TrackPoint, and can't go back to other laptops for work (some HP models had it at one point, but I haven't seen it in recent ones).

And, sure, USB killed PCMCIA, but I still prefer the embedded form factor and standard size of PC cards. Now we have a million USB devices, all with different form factors, and even different behavior depending on the USB standard they support. At least we've sort of settled on a single connector now.

Re: How to Yubikey

#113
post #98

Earlier quoted context omitted.

do any other keys have feature sets on par with yubikeys? last i checked they were ahead by a mile, the others i looked at were just fido2 keys

so far, Yubikeys are the only ones I've found that support both FIDO2 / WebAuthn as well as GPG smart card functionality for use with pass(1). they also support ed25519 FIDO SSH keys, whereas all the cheapo FIDO keys I've tested only support ecdsa-nistp256, but that's a relatively minor difference. Nitrokey 3 claims that GPG smart card support is planned in an upcoming firmware update. once that's released I may bite…

Also, yubikey works as a PIV smartcard

Re: How to Yubikey

#114
post #92

Earlier quoted context omitted.

It works for Safari. For AWS, I use Firefox and a FIDO key, and have a backup MFA as Safari using U2F.

If Secure Enclave is as secure as Apple claims it to be, Safari‘s option might actually be the safest one. Of course you can’t use that on anything other than a Mac or iPhone, so in some situations you need another key.

It's a bit more specific than that, no?

You can't use Safari's option on anything other than that particular Mac or iPhone. It's my understanding that you can't extract the secret key from the secure enclave.

Re: How to Yubikey

#115
post #44

Earlier quoted context omitted.

> Nobody seems to reflect that if you physically steal the laptop, guess what, the usb key that's still in there was also stolen. Not in how I use it. I only connect my yubikey when I need it (rarely at that). > right? Right? Just generally don't do this. It comes of as unnecessarily aggressive. Instead you could say "Do use USB locks on your laptop, because ....". The "right? Right?" is not making your point more pe…

> Just generally don't do this. It comes of as unnecessarily aggressive. Instead you could say "Do use USB locks on your laptop, because ....". The "right? Right?" is not making your point more persuasive. Pot, kettle situation?

I don't see it that way, but happy to be corrected. Please tell me which part do you feel is unnecessarily aggressive? Just the general concept of asking someone to communicate differently, or a particular part of my message?

Re: How to Yubikey

#116
post #65

Earlier quoted context omitted.

I’ve carried a USB-A Yubikey in my pocket for 7 years and it’s never broke. I also keep one time login passwords encrypted and available in the cloud in the event I lose the key.

I've had one USB-C key break on me in the past, and my replacement is already showing signs of wear. Fortunately it's not my only way to get back into my accounts if it breaks. My (sample size 2) theory is that USB-C isn't the best connector for a security key, since it intentionally moves the wear-prone part (i.e. the dust-collecting and mechanical spring involving side) from the port to the cable. USB-A is complete…

For a security key, sure, it's better for that side of the USB port to be more resistant.

But on the PC side, my old HP laptop used to have extremely tight USB A ports. I'd have to pull ridiculously hard on cables to disconnect them. Now the ports are fairly loose, to the point that my external drive sometimes disconnects...

The yubikey kinda dances around in that port. Luckily, I don't move the laptop too much, so the key tends to stay put, but it sometimes does lose contact out when I need to touch it often.

Re: How to Yubikey

#117
post #110
post #11

Earlier quoted context omitted.

or SoloKey

I've found Solokey to be unreliable. Recently, for example, I learned that the Solokey 2 can't be added to iCloud as a security key

I have multiple Solo Key 2 devices. (I bought a Kickstarter 4-pack.) I use one of them regularly, and I successfully added it to iCloud as a security key. It has been 100% reliable.

In August 2022 they released a major firmware update. Maybe that addressed the iCloud incompatibility and reliability issues?

Re: How to Yubikey

#118
Someone needs to do this but for a windows environment. The documentation is a disaster in that realm. Took me forever to get it working properly with active directory.

Re: How to Yubikey

#119
post #98
post #5

Reminder: Yubico doesn't have a monopoly on security keys. Make sure your software/tutorials support the open-source alternatives like OnlyKey and NitroKey.

do any other keys have feature sets on par with yubikeys? last i checked they were ahead by a mile, the others i looked at were just fido2 keys

[deleted]

Re: How to Yubikey

#120

Earlier quoted context omitted.

Aren't you always vulnerable in this scenario? If you have your device in your possession, you also likely have your key in your possession in order to use your device.

If your threat profile really includes the possibility of getting hit by a wrench, you can devise a means of destroying the key quickly.

My YubiKey seems pretty rugged, which is why I feel okay carrying it on my (physical) keychain.
Post reply on HN