Live data from Hacker News

Support for U2F security keys

blog.1password.com

131–140 of 164 posts

Re: Support for U2F security keys

#131

Earlier quoted context omitted.

My college uses Duo and it has no such restriction, if you tried this recently and couldn't add more than 1, it is probably set by LastPass/1Password.

Duo Free used to have a restriction of one device, but it seems for U2F they now require one of their paid plans: https://duo.com/product/trusted-users/two-factor-authenticat...

I didn't even realize they had a free tier, makes sense.

Re: Support for U2F security keys

#132
post #130

Earlier quoted context omitted.

I'm selling water bottles at $100/gallon. Considering water is literally essential to life, how many can I get you?

You must have had better ones than _that_, when you were thinking up a witty reply. I hope that wasn't you bringing your best.

What immodesty; to presume oneself to be worthy of the best.

Re: Support for U2F security keys

#133

only tangential, but I've wanted to carry my Yubikey on my keyring, but have always been nervous about making it unreadable by sullying the contacts. Should I be concerned about this? Where do you all carry them?

I’ve hade one for 10 years or more and it’s fine. It’s a durable little thing.

Re: Support for U2F security keys

#134
post #130

Earlier quoted context omitted.

You must have had better ones than _that_, when you were thinking up a witty reply. I hope that wasn't you bringing your best.

What immodesty; to presume oneself to be worthy of the best.

Rather: why half-ass anything in life?

Re: Support for U2F security keys

#135
post #56

Earlier quoted context omitted.

The way $dayjob makes this work is to issue a nano security key for each computer, and then a bluetooth security key for the iPhone (Android phones can use both NFC and Bluetooth security keys, but iPhones can only use Bluetooth security keys). It's cumbersome, but less so than when we were plugging and unplugging our one hardware USB-A OTP token into everything (and using a desktop web browser to generate OTPs for t…

What happens if your house burns down with everything in it? You’d then have to contact support to let you bypass 2FA, but if that’s possible then the 2FA protection is weak, prone to social hacking.

"if your house burns down with everything in it, you'd have to call somebody" seems like a fairly ridiculous concern.

Re: Support for U2F security keys

#136

Earlier quoted context omitted.

What happens if your house burns down with everything in it? You’d then have to contact support to let you bypass 2FA, but if that’s possible then the 2FA protection is weak, prone to social hacking.

"if your house burns down with everything in it, you'd have to call somebody" seems like a fairly ridiculous concern.

That's not their argument. Please read the last bit of the sentence again.

Re: Support for U2F security keys

#137
post #111

Earlier quoted context omitted.

Well, yes, that is exactly what I'm talking about. The biggest advantage of a physical second factor is that I can see if it has been stolen: I either have it with me, or I don't. By using multiple keys, you are effectively removing that advantage: someone could have one of your devices (e.g. your laptop while you're out for lunch) and would be able to make use of your second factor without you knowing.

Well if your primary concern is a local threat - which it absolutely is not for the vast majority of people - then you just have to be more careful with your keys. If you suspect someone might be actively trying to break in to your home, you wouldn’t leave your keys on your desk while you went to lunch.

You can also add PINs to Yubikeys to mitigate the local threat.

Re: Support for U2F security keys

#138
post #50
post #37

Earlier quoted context omitted.

Autofill of a password manager is a working countermeasure against phishing too: If autofill does not work there is something wrong and you should look closer...

I can't find a source, but my recollection is that Google developed U2F because autofill didn't work reliably enough, so many users would just paste the password manually anyway.

It doesn't matter whether the technology "works reliably enough" it matters whether the _user_ reliably won't sidestep security by pasting their password in to the phishing site. And that's something we knew the answer to decades ago: No.

Humans are bad at giving up. If there seems to be a way forward for the original plan they will press on, regardless of all indications that this now a bad idea. In fact Google had a security override in Chrome for years that was literally typing the sequence "badidea" in recognition of this. It's not specific to computer security, it happens in incident management, there's a seminal example from years back where a train breaks down, and the incident manager sees that step 1 of the response is to send a recovery train to the location, and literally _hours_ later, with passengers stranded and desperate - that manager was still wrestling with how to get the recovery train to the location so they could proceed to step 2, rather than realising that problems with the recovery train meant they needed to _abandon the entire plan and re-assess_ because humans are not good at that.

Re: Support for U2F security keys

#139
post #56
post #25

I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?

The way $dayjob makes this work is to issue a nano security key for each computer, and then a bluetooth security key for the iPhone (Android phones can use both NFC and Bluetooth security keys, but iPhones can only use Bluetooth security keys). It's cumbersome, but less so than when we were plugging and unplugging our one hardware USB-A OTP token into everything (and using a desktop web browser to generate OTPs for t…

NFC keys should work for iOS, too, now:

https://9to5mac.com/2018/05/22/yubikey-neo-iphone-lastpass/

Re: Support for U2F security keys

#140
post #19

Earlier quoted context omitted.

How do you manage keeping all the keys "synced" in terms of which services they are registered with. I keep keys in separate locations for safety, but that makes adding all keys to a new account a big pain. This hasn't been a big problem yet because there are so few services that support the keys, but I wonder how people would manage it if it became widespread.

It's a pain, I don't have a good answer. What I'm going to do personally is only use U2F on my most secure services (email, 1Password itself, GitHub). 1Password with the TOTP stored inside of it should be good enough for the others.

I like this hierarchical approach. Thanks.
Post reply on HN