Live data from Hacker News

YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

yubico.com

141–150 of 187 posts

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#141
post #72
post #45

Earlier quoted context omitted.

IMHO the YubiKey is not useful for any of those. It's excellent for storing OpenPGP keys and U2F, reasonably good for X.509 (as much as expected for X.509 I guess), and not good for much else. Using it for TOTP IMHO makes no sense, it's better to use your phone.

Using it for TOTP makes sense if you have more than one phone or want to use TOTP on your desktop through Yubico authenticator.

Exactly. Additionally phones can be rooted and that exposes the underlying secret but Yubikeys are tamper resistant.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#143
post #57

I think the YK5's biggest problem is that the YK Neo and 4, which have been out for years, were already so good. Unless you really care about NFC at the same time as RSA-4096, I'm not sure I see a big impetus to upgrade. Hopefully the USB-C line won't be plagued with supply issues. WebAuthn is mostly boring and I think that's mostly a good thing. I'm glad that there's a way to evolve the spec. Some of the changes are…

The feature the 4 has which the Neo doesn't which matters most to me is 'touch to confirm key operation' when used via USB. I'm quite surprised how little this seems to be known - a hardware key which will sign anything a potential piece of malware or malicious actor asks for without question (assuming said malware is able to steal the PIN or get access to the appropriate agent socket which is not too much of a stret…

This makes sense for enterprise uses where an organization wants to keep private key material off a server, but don't want to spend the money for a enterprise security key manager.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#144
post #138
post #118

Earlier quoted context omitted.

> the YK Neo and 4, which have been out for years, were already so good I agree that the keys themselves are good; I just wish that configuring Linux systems to take advantage of them would be easier. I've been working on setting my systems up in bits of my free time for more than a month now. I'm in my last stretch, but I have to do some weird things. Maybe I'm just trying to squeeze more out of the key than most wo…

>For example, when I'm in my laptop and I ssh to my desktop and use sudo, I want it to use the key connected to the laptop to authenticate me. At the same time, if I walk over to the desktop and use sudo, I want it to seek the key in the desktop. Same if I use gpg or anything else that wants to use the key. This can easily be done, I do it all the time. You have to set up both YKs to have the same PGP keys and then u…

That would be enough, if I would compromise to forego use of sudo and relogin with ssh as root. I really would preper to keep the ability to only sudo the parts of composed commands that need it in my non-root shell session, though, which is why I'm still looking into this.

This effort will also allow me to use gpg and the programs that depend on it like my password manager, pass, to use the correct agent.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#145
post #72
post #45

Earlier quoted context omitted.

IMHO the YubiKey is not useful for any of those. It's excellent for storing OpenPGP keys and U2F, reasonably good for X.509 (as much as expected for X.509 I guess), and not good for much else. Using it for TOTP IMHO makes no sense, it's better to use your phone.

Using it for TOTP makes sense if you have more than one phone or want to use TOTP on your desktop through Yubico authenticator.

Authy is excellent for this. I've got it on my phone and tablet. I'm reluctant to use it on my desktop because I don't want to type in a huge password but I regard my 2015 MacBook as less secure than my devices that are protected by touch. You might be OK with that or have a laptop with touch ID.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#146
post #67

Earlier quoted context omitted.

The 5C nano is designed to be plugged in the all the time though, so in that scenario what do you really gain from NFC?

Because one day we'd like to securely authenticate to things on phones in phone browsers. (I agree that it's not a big a deal as one may think; it only matters if you're logging in to a critical service via the browser and not the app. If you're using the app, it's the app's problem to make sure that you're talking to the Correct Service(TM), so phishing concerns go away.)

[deleted]

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#147
post #133

Earlier quoted context omitted.

The feature the 4 has which the Neo doesn't which matters most to me is 'touch to confirm key operation' when used via USB. I'm quite surprised how little this seems to be known - a hardware key which will sign anything a potential piece of malware or malicious actor asks for without question (assuming said malware is able to steal the PIN or get access to the appropriate agent socket which is not too much of a stret…

Wait, seriously? Not even the OpenPGP applet/with ykman configuration? In what modes does it do that? That’s send-it-back bad.

Certainly for the OpenPGP applet, require touch to sign/auth/enc was introduced with the Yubikey 4. For U2F touch is always required and you do get an option on the NEO to require touch for Yubico challenge/response. Not sure about the PIV or TOTP applets.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#149

Earlier quoted context omitted.

The feature the 4 has which the Neo doesn't which matters most to me is 'touch to confirm key operation' when used via USB. I'm quite surprised how little this seems to be known - a hardware key which will sign anything a potential piece of malware or malicious actor asks for without question (assuming said malware is able to steal the PIN or get access to the appropriate agent socket which is not too much of a stret…

This makes sense for enterprise uses where an organization wants to keep private key material off a server, but don't want to spend the money for a enterprise security key manager.

Yes - I'm not saying it shouldn't be possible to configure it that way but it is not great that (at least for OpenPGP) there's no way to set it to require physical interaction to gain access to key functions on the NEO.

Re: YubiKey 5 Series with New NFC and FIDO2 Passwordless Features

#150
post #67

Earlier quoted context omitted.

The 5C nano is designed to be plugged in the all the time though, so in that scenario what do you really gain from NFC?

Because one day we'd like to securely authenticate to things on phones in phone browsers. (I agree that it's not a big a deal as one may think; it only matters if you're logging in to a critical service via the browser and not the app. If you're using the app, it's the app's problem to make sure that you're talking to the Correct Service(TM), so phishing concerns go away.)

Contrary to (at least the 4 series-era) Yubico's marketing materials, their Android app works fine with USB (in fact better than with NFC), so if you have and Android phone with a USB-C port, you can plug in a USB-C Yubikey directly (or a USB-A Yubikey with an adapter).

Once browsers on Android support WebAuthn, it may well be that plugging in a USB-C Yubikey will be more convenient than trying to locate the position of the NFC antenna.

Post reply on HN