Live data from Hacker News

How to Yubikey

debugging.works

121–130 of 186 posts

Re: How to Yubikey

#121
post #92

Earlier quoted context omitted.

If Secure Enclave is as secure as Apple claims it to be, Safari‘s option might actually be the safest one. Of course you can’t use that on anything other than a Mac or iPhone, so in some situations you need another key.

It's a bit more specific than that, no? You can't use Safari's option on anything other than that particular Mac or iPhone. It's my understanding that you can't extract the secret key from the secure enclave.

I don't know how this certain feature is implemented. But Pass Keys are synced via iCloud and the private key never leaves any Secure Enclave in unencrypted form. Maybe these virtual security keys are different in that they are never synced via iCloud, but principally they could be.

Re: How to Yubikey

#122
post #98
post #5

Reminder: Yubico doesn't have a monopoly on security keys. Make sure your software/tutorials support the open-source alternatives like OnlyKey and NitroKey.

do any other keys have feature sets on par with yubikeys? last i checked they were ahead by a mile, the others i looked at were just fido2 keys

If they don't, that's more of a reason to use the OTHERS? You really don't want a monoculture here.

Re: How to Yubikey

#124

Earlier quoted context omitted.

Aren't you always vulnerable in this scenario? If you have your device in your possession, you also likely have your key in your possession in order to use your device.

If your threat profile really includes the possibility of getting hit by a wrench, you can devise a means of destroying the key quickly.

Also if the wrench is a consideration, you really need to consider at what point you die rather than reveal.

And note that you may die even if you want to reveal; especially if you've setup a system that prevents you from revealing (two person keys, etc).

Re: How to Yubikey

#125
post #35
post #28

Your paranoia is getting out of hand, seriously. 2FA here, OTP there. Idk about you, maybe you do have such sensitive data that you have to double guard everything, I and the usual average guy doesn't. Why do I care? Because this craze has already reached the real world. Amazon requiring 2FA on deliveries. Wtf is wrong with my passport or other document? Nothing. Now I have to be physically present and recite some fu…

My World of Warcraft account had been secured by 2FA 10y earlier than my bank account. The good thing is, the launcher app on _my_ PC got the feature (a few years ago) that I only need to use the actual 2FA fob once every few months, not every time I login. It protects me against the most common case (someone logging in with my account/stealing my account) while not getting in the way at all. Unless someone breaks in…

The whitelisting is really nice, and it's expanding more and more. I like "login once per device".

Re: How to Yubikey

#126
I've gotten good mileage over the last 5 years from drduh's guide to using Yubikeys with GPG and SSH. Works great, fully compatible.

The new fangled ed25519 stuff simply didn't work for me.

Re: How to Yubikey

#127
post #5

Reminder: Yubico doesn't have a monopoly on security keys. Make sure your software/tutorials support the open-source alternatives like OnlyKey and NitroKey.

I’m unclear as to why we can’t use some sort of tpm for webauthn and distributed encrypted passwords for synchronisation.

Hell, even software based implementations which force domain checking would solve 99% of the problem…

Re: How to Yubikey

#128
post #5

Reminder: Yubico doesn't have a monopoly on security keys. Make sure your software/tutorials support the open-source alternatives like OnlyKey and NitroKey.

Mullvad VPN has announced that their sister company "Tillitis"[1] is working on a really interesting key and it looks like it's releasing pretty soon (2023-03-23).

From the website:

>The TKey™ is a new kind of USB security key inspired by measured boot and DICE.

>TKey™s design encourages developers to experiment with new security key applications and models in a way that makes adoption easier and less risky forend-users.

>TKey™ is and always will be open source hardware and software. Schematics, PCB design and FPGA design source as well as all software source code can be found on GitHub.

[1]: https://www.tillitis.se/ -- also "tillit" is Swedish for "trust" and "mullvad" is Swedish for "mole" (the animal).

Re: How to Yubikey

#129
post #122
post #98

Earlier quoted context omitted.

do any other keys have feature sets on par with yubikeys? last i checked they were ahead by a mile, the others i looked at were just fido2 keys

If they don't, that's more of a reason to use the OTHERS? You really don't want a monoculture here.

i would be happy to use the OTHERS if they were comparable products

Re: How to Yubikey

#130

I like the idea of securitykeys, but having to drop 100€ for a key (since in my opinion you are playing with fire if you don't buy a backup) feels like excessive and then having to worry that I remember to take my securitykey with me everywhere... Yeah, yeah, security vs. convenience is always the issue, but so far I've just selected convenience.

[dead]
Post reply on HN