Live data from Hacker News

Support for U2F security keys

blog.1password.com

121–130 of 164 posts

Re: Support for U2F security keys

#121
post #111

Earlier quoted context omitted.

Not unless your attacker has physical access to the machine. You still have to touch the device to activate it each time. This still mitigates the most common MITM-type attacks: 1. Attacker instigates login via fake portal. 2. Attacker fools you in to entering your 6-digit OTP. 3. Attacker intercepts your valid OTP, combines with your stolen password, logs in to real site. This doesn’t work with a YubiKey or the equi…

Well, yes, that is exactly what I'm talking about. The biggest advantage of a physical second factor is that I can see if it has been stolen: I either have it with me, or I don't. By using multiple keys, you are effectively removing that advantage: someone could have one of your devices (e.g. your laptop while you're out for lunch) and would be able to make use of your second factor without you knowing.

That's true. But if the alternative is that people have to setup weaker fallback mechanisms (such as SMS verification) then I'm happy to pay that price.

Re: Support for U2F security keys

#122

only tangential, but I've wanted to carry my Yubikey on my keyring, but have always been nervous about making it unreadable by sullying the contacts. Should I be concerned about this? Where do you all carry them?

After about 6 months of use, my blue Yubikey is tarnished but functions as intended.

Re: Support for U2F security keys

#123

Earlier quoted context omitted.

Before this, both LastPass and 1Password said they supported U2F via Duo, but Duo only supported one key, so I could never use it.

My college uses Duo and it has no such restriction, if you tried this recently and couldn't add more than 1, it is probably set by LastPass/1Password.

Duo Free used to have a restriction of one device, but it seems for U2F they now require one of their paid plans: https://duo.com/product/trusted-users/two-factor-authenticat...

Re: Support for U2F security keys

#124
post #95
post #64

I switched recently to Bitwarden. 1Passwords pricing/subscription changes was the the push I needed. Bitwarden has been fantastic, I highly recommend it. https://bitwarden.com

$2.99 per month is too steep of a price to pay for your personal security? Really? I'd dump my Spotify/Apple Music/Netflix/whatever in a heartbeat, if I had to choose between paid subscriptions in my life

I'm selling water bottles at $100/gallon. Considering water is literally essential to life, how many can I get you?

Re: Support for U2F security keys

#125
post #111

Earlier quoted context omitted.

Not unless your attacker has physical access to the machine. You still have to touch the device to activate it each time. This still mitigates the most common MITM-type attacks: 1. Attacker instigates login via fake portal. 2. Attacker fools you in to entering your 6-digit OTP. 3. Attacker intercepts your valid OTP, combines with your stolen password, logs in to real site. This doesn’t work with a YubiKey or the equi…

Well, yes, that is exactly what I'm talking about. The biggest advantage of a physical second factor is that I can see if it has been stolen: I either have it with me, or I don't. By using multiple keys, you are effectively removing that advantage: someone could have one of your devices (e.g. your laptop while you're out for lunch) and would be able to make use of your second factor without you knowing.

Well if your primary concern is a local threat - which it absolutely is not for the vast majority of people - then you just have to be more careful with your keys. If you suspect someone might be actively trying to break in to your home, you wouldn’t leave your keys on your desk while you went to lunch.

Re: Support for U2F security keys

#126
post #56

Earlier quoted context omitted.

The way $dayjob makes this work is to issue a nano security key for each computer, and then a bluetooth security key for the iPhone (Android phones can use both NFC and Bluetooth security keys, but iPhones can only use Bluetooth security keys). It's cumbersome, but less so than when we were plugging and unplugging our one hardware USB-A OTP token into everything (and using a desktop web browser to generate OTPs for t…

What happens if your house burns down with everything in it? You’d then have to contact support to let you bypass 2FA, but if that’s possible then the 2FA protection is weak, prone to social hacking.

Most sites let you set up both the Yubikey and a Google auth style TOTP. I always set up both, with TOTP codes saved in KeePassXC and SFTP'd to a backup server.

Re: Support for U2F security keys

#127
post #37

Earlier quoted context omitted.

Autofill of a password manager is a working countermeasure against phishing too: If autofill does not work there is something wrong and you should look closer...

Until the next exploit that can steal passwords from autofill...

I have to click a button in the extension to get it to fill. Not quite Auto fill, but pretty close.

Re: Support for U2F security keys

#128

Earlier quoted context omitted.

I keep an extra Yubikey in my bank box, next to my other backup keys. The only account I'd be locked out of is Twitter since they only let you add 1 token (my primary).

AWS also only allows you to add a single device, much to my annoyance. I still haven’t found a solution for that, that doesn’t involve risking getting locked out.

One answer I've seen is to create multiple users for the same person. The second user becomes the "backup" user with a different physical device and is used only to reset the primary.

Re: Support for U2F security keys

#129
post #37
post #16

Earlier quoted context omitted.

The primary purpose of U2F/WebAuthn is to break phishing attacks. Code-based TOTP 2FA, the kind you're probably using now, is already adequate to the task of making sure you're not credential-stuffed.

Autofill of a password manager is a working countermeasure against phishing too: If autofill does not work there is something wrong and you should look closer...

Unless DNS is compromised.

Re: Support for U2F security keys

#130
post #95

Earlier quoted context omitted.

$2.99 per month is too steep of a price to pay for your personal security? Really? I'd dump my Spotify/Apple Music/Netflix/whatever in a heartbeat, if I had to choose between paid subscriptions in my life

I'm selling water bottles at $100/gallon. Considering water is literally essential to life, how many can I get you?

You must have had better ones than _that_, when you were thinking up a witty reply. I hope that wasn't you bringing your best.
Post reply on HN