Earlier quoted context omitted.
Not unless your attacker has physical access to the machine. You still have to touch the device to activate it each time. This still mitigates the most common MITM-type attacks: 1. Attacker instigates login via fake portal. 2. Attacker fools you in to entering your 6-digit OTP. 3. Attacker intercepts your valid OTP, combines with your stolen password, logs in to real site. This doesn’t work with a YubiKey or the equi…
Well, yes, that is exactly what I'm talking about. The biggest advantage of a physical second factor is that I can see if it has been stolen: I either have it with me, or I don't. By using multiple keys, you are effectively removing that advantage: someone could have one of your devices (e.g. your laptop while you're out for lunch) and would be able to make use of your second factor without you knowing.
Support for U2F security keys
121–130 of 164 posts
Re: Support for U2F security keys
#122only tangential, but I've wanted to carry my Yubikey on my keyring, but have always been nervous about making it unreadable by sullying the contacts. Should I be concerned about this? Where do you all carry them?
Re: Support for U2F security keys
#123Earlier quoted context omitted.
Before this, both LastPass and 1Password said they supported U2F via Duo, but Duo only supported one key, so I could never use it.
My college uses Duo and it has no such restriction, if you tried this recently and couldn't add more than 1, it is probably set by LastPass/1Password.
Re: Support for U2F security keys
#124I switched recently to Bitwarden. 1Passwords pricing/subscription changes was the the push I needed. Bitwarden has been fantastic, I highly recommend it. https://bitwarden.com
$2.99 per month is too steep of a price to pay for your personal security? Really? I'd dump my Spotify/Apple Music/Netflix/whatever in a heartbeat, if I had to choose between paid subscriptions in my life
Re: Support for U2F security keys
#125Earlier quoted context omitted.
Not unless your attacker has physical access to the machine. You still have to touch the device to activate it each time. This still mitigates the most common MITM-type attacks: 1. Attacker instigates login via fake portal. 2. Attacker fools you in to entering your 6-digit OTP. 3. Attacker intercepts your valid OTP, combines with your stolen password, logs in to real site. This doesn’t work with a YubiKey or the equi…
Well, yes, that is exactly what I'm talking about. The biggest advantage of a physical second factor is that I can see if it has been stolen: I either have it with me, or I don't. By using multiple keys, you are effectively removing that advantage: someone could have one of your devices (e.g. your laptop while you're out for lunch) and would be able to make use of your second factor without you knowing.
Re: Support for U2F security keys
#126Earlier quoted context omitted.
The way $dayjob makes this work is to issue a nano security key for each computer, and then a bluetooth security key for the iPhone (Android phones can use both NFC and Bluetooth security keys, but iPhones can only use Bluetooth security keys). It's cumbersome, but less so than when we were plugging and unplugging our one hardware USB-A OTP token into everything (and using a desktop web browser to generate OTPs for t…
What happens if your house burns down with everything in it? You’d then have to contact support to let you bypass 2FA, but if that’s possible then the 2FA protection is weak, prone to social hacking.
Re: Support for U2F security keys
#127Earlier quoted context omitted.
Autofill of a password manager is a working countermeasure against phishing too: If autofill does not work there is something wrong and you should look closer...
Until the next exploit that can steal passwords from autofill...
Re: Support for U2F security keys
#128Earlier quoted context omitted.
I keep an extra Yubikey in my bank box, next to my other backup keys. The only account I'd be locked out of is Twitter since they only let you add 1 token (my primary).
AWS also only allows you to add a single device, much to my annoyance. I still haven’t found a solution for that, that doesn’t involve risking getting locked out.
Re: Support for U2F security keys
#129Earlier quoted context omitted.
The primary purpose of U2F/WebAuthn is to break phishing attacks. Code-based TOTP 2FA, the kind you're probably using now, is already adequate to the task of making sure you're not credential-stuffed.
Autofill of a password manager is a working countermeasure against phishing too: If autofill does not work there is something wrong and you should look closer...
Re: Support for U2F security keys
#130Earlier quoted context omitted.
$2.99 per month is too steep of a price to pay for your personal security? Really? I'd dump my Spotify/Apple Music/Netflix/whatever in a heartbeat, if I had to choose between paid subscriptions in my life
I'm selling water bottles at $100/gallon. Considering water is literally essential to life, how many can I get you?