Live data from Hacker News

Strengthening 2-Step Verification with Security Key

googleonlinesecurity.blogspot.com

111–120 of 150 posts

Re: Strengthening 2-Step Verification with Security Key

#111

Some comments are pointing out how awkward this might be, > I don't see a point in plugging my entire keychain (the physical keychain, with my car keys) into my laptop every time I want to log in > I'm not sure about having to plug it in every time I'll share my experience. I use two of these on a laptop and desktop and I have never unplugged them; there's no reason to. They sit very flush in the USB slot. I suppose…

> I use two of these on a laptop and desktop and I have never unplugged them; there's no reason to.

I use a Yubikey for ${WORK} and we are required to remove such tokens as soon as they have fulfilled their purpose. On pain of disciplinary action, as it is considered on par with leaving a password on a Post-it.

Otherwise there's no point in them as an additional security step in the event that the laptop is lost or stolen.

Re: Strengthening 2-Step Verification with Security Key

#112
post #77

Cool, but I will continue using the Google Authenticator app. Google is not the only thing that requires 2FA, so do numerous other sites, and GA app is the most widely supported and the least pain in the behind. I don't see a point in plugging my entire keychain (the physical keychain, with my car keys) into my laptop every time I want to log into GMail, much less carrying around 10+ different USB tokens. Now, a NFC-…

IMHO the Authy app is nicer than Google Authenticator. https://play.google.com/store/apps/details?id=com.authy.auth... http://itunes.apple.com/us/app/authy/id494168017?mt=8

redhat also makes a prettier version (https://play.google.com/store/apps/details?id=org.fedorahost...). not as pretty as authy, but less sketchy w/ the pointless permissions. Also, authy cloud syncs your accounts which seems like a bad idea.

Re: Strengthening 2-Step Verification with Security Key

#113

Earlier quoted context omitted.

Also this though: > Security Key and Chrome incorporate the open Universal 2nd Factor (U2F) protocol from the FIDO Alliance, so other websites with account login systems can get FIDO U2F working in Chrome today. It’s our hope that other browsers will add FIDO U2F support, too.

If you share the same FIDO U2F key between services, does that mean that one service could spoof tokens for a different service? e.g. foo gets compromised, so attackers can generate codes for google apps.

No. There are no shared secrets. This is real asymmetric crypto.

Re: Strengthening 2-Step Verification with Security Key

#114
post #109

Cool, but I will continue using the Google Authenticator app. Google is not the only thing that requires 2FA, so do numerous other sites, and GA app is the most widely supported and the least pain in the behind. I don't see a point in plugging my entire keychain (the physical keychain, with my car keys) into my laptop every time I want to log into GMail, much less carrying around 10+ different USB tokens. Now, a NFC-…

Don't keep it on the same keychain as your car keys. I don't–that would be terribly impractical. Instead, it lives in my laptop slipcase. Even better, get the nano version and leave it in your USB slot permanently: http://www.amazon.com/dp/B00O8ST7MM

Isn't this kind of counterproductive? A key use case of 2FA is to keep your accounts secure if your computer is simply stolen.

Re: Strengthening 2-Step Verification with Security Key

#115
post #95

No one has mentioned the coolest feature of U2F/Fido auth: TLS Channel IDs. Via an internal Chrome extension ("cryptotoken"), authentication state & the handshake can be bound to a specific TLS session -- preventing cookie theft. Incredibly cool: http://www.browserauth.net/channel-bound-cookies

This is indeed a cool feature. I hadn't been aware of it until now. I see that Dirk Balfanz from Google published a IETF draft a couple years ago.

I need to digest the security implications, but it seems like a nice mitigation to session theft.

Re: Strengthening 2-Step Verification with Security Key

#116

Good luck plugging a USB key into your iPad, or letting your security-sensitive workplace let you plug arbitrary USB keys into your workstation, or convincing your bank that you really did not send your entire balance to Nigeria, even though you signed that transaction with a tap, etc etc... Remember Mt.Gox? That's Yubico's most public failure so far :-) Strong authentication needs to be out-of-band, and support tran…

I think its pretty obvious that anything without a USB connection this probably won't work (maybe usb otg), but would 2FA still be used as a fall back ?

You can get NFC enabled keys to use with any device without USB that supports NFC

Re: Strengthening 2-Step Verification with Security Key

#117
post #109

Earlier quoted context omitted.

Don't keep it on the same keychain as your car keys. I don't–that would be terribly impractical. Instead, it lives in my laptop slipcase. Even better, get the nano version and leave it in your USB slot permanently: http://www.amazon.com/dp/B00O8ST7MM

Isn't this kind of counterproductive? A key use case of 2FA is to keep your accounts secure if your computer is simply stolen.

You can revoke that key if your computer is stolen.

Re: Strengthening 2-Step Verification with Security Key

#118
post #77

Earlier quoted context omitted.

IMHO the Authy app is nicer than Google Authenticator. https://play.google.com/store/apps/details?id=com.authy.auth... http://itunes.apple.com/us/app/authy/id494168017?mt=8

Maybe the UI is nicer, but the permissions on Android are unnecessarily intrusive, which—to me—is a dealbreaker with a 2FA manager . Device & app history read sensitive log data Identity find accounts on the device Camera/Microphone take pictures and videos Wi-Fi connection information view Wi-Fi connections Other receive data from Internet access Bluetooth settings pair with Bluetooth devices full network access vie…

Well, each of those permissions they request ties to a very obvious and useful feature.

Camera/Photo for QR code-based 2FA, Bluetooth permissions and Internet Data to handle local connection to trusted machines and callbacks from sites like Coinbase (when I log into coinbase, I get a handy 2fa notification from authy that leads me right to the code)

Log data is the most questionable, but it really makes debugging so much easier when you can see what's going on, and is a pattern/permission they share with Evernote, foursquare, fring, Netflix, Rdio, Dolphin Browser, AccuWeather.com, Hotmail, doubleTwist Player, MOG, Handcent SMS, Bump, TweetCaster, etc.

Re: Strengthening 2-Step Verification with Security Key

#119
post #53
post #16

Earlier quoted context omitted.

I've never used it but, https://www.yubico.com/products/yubikey-hardware/yubikey-neo... seems to fit the bill.

I have one. It is pretty cool but it hasn't been real useful up until now. I haven't found many apps that support it. I ended up just grabbing the clipboard app that yubikey puts out. I tried using the static password feature by using it as part of my master password in 1password but the newer versions of 1password block using the clipboard in android (with good reason). It would be pretty awesome if password-manager…

LastPass supports Yubikey natively, including on mobile.

Re: Strengthening 2-Step Verification with Security Key

#120

Earlier quoted context omitted.

Google is supporting the FIDO U2F standard just like Yubikey now.

They pay upwards of $100k+ per year to have a seat on the board and direct the "standard" to suit their products.

Your comment reads as if you believe that having an authentication standard that suits the products of the largest webmail provider is somehow bad. I'm having trouble understanding this. Better suiting the use-case of things like gmail seems like unequivocally a good thing. (As does the consortium being better funded by $100k+ a year, for that matter.)
Post reply on HN