Live data from Hacker News

Yubico launches its dual USB-C and Lightning two-factor security key

techcrunch.com

161–170 of 178 posts

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#161
post #97

Earlier quoted context omitted.

Do not store your 2FA codes in 1Password. It turns your second factor into the same one as your password. I was storing backup codes in 1P before I realized that I was putting all my eggs in one proverbial basket.

Not quite - if someone steals your 1Password (or equivalent) database with TOTP seeds in, they need to crack the password on that, then have full access to everything. If they get the password from the other end (e.g. the site you log into), they can probably log into that specific site (they will have the TOTP seed), but not anything else. In general, there are more attackers looking at the site end than at the clie…

Since, once unlocked, 1password as of version 7 stores everything de-crypted in memory, ANY attack on a host with an unlocked 1password keychain which can exfiltrate memory across processes can steal everything.

It's pretty obvious why this changed, however, it is a major increase in exposure and a terrible change overall. It is discussed in [1] and mostly the answers aren't very satisfying as demonstrated in [2].

[1] https://discussions.agilebits.com/discussion/101560/secure-m...

[2] https://discussions.agilebits.com/discussion/101551/article-...

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#162
post #6

I think I'd preferred if they offered a USB-C and USB-A combo.

We've got a few people asking for double USB-A+C when we launched Solo, but I personally don't feel particularly excited about a dual plug key.

This said, if anyone here would like to give it a shot... our hardware is open source so relatively easy to add both plugs, firmware should just work, and I'm happy to support with manufacturing. I would highly recommend to test the market first (landing page, or even crowdfunding campaign).

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#163
post #119

Earlier quoted context omitted.

From what I've heard from Yubico the next version of iOS is going to make it far easier to communicate with the device. Integrations will probably still need to be added by the app developers though to take full advantage.

Do you know whether that includes websites in Safari? If I can’t use 2FA for that, I don’t see how I can use a Yubikey.

Apple appears to be working to add WebAuthn support to Safari. See https://appleinsider.com/articles/18/12/05/apple-testing-usb...

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#164
post #119

Earlier quoted context omitted.

From what I've heard from Yubico the next version of iOS is going to make it far easier to communicate with the device. Integrations will probably still need to be added by the app developers though to take full advantage.

Do you know whether that includes websites in Safari? If I can’t use 2FA for that, I don’t see how I can use a Yubikey.

It's hard to say until we see it in action. I'm optimistic, but with Apple's track record of hobbling integrations in annoying ways I'm still a little hesitant.

I really do want them to work fully though so I can extend my product to mobile too. I know a lot of people now that have gotten rid of their computers and just use their phones for everything.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#165
post #75

I actually had the chance to try out a prototype at Blackhat. I was actually able to have the USB-C portion recognized on my Android Phone (via the USB port), and it was recognized in Firefox and lsusb (though for some reason I was unable to register it, and I has the u2f enabled in about:config). I am tempted to buy it to see if I could get it to work on my phone, I would much rather have the USB-C work on my phone…

Any usb-c key should work on Android. Firefox has been recently updated to support webauthn, so you no longer have to turn u2f on. Note that some sites, like Google, only allow you to register the key on Chrome, but then you can use it on Firefox too.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#166
post #148

Does the 5C/Nano work with Android phones with USB-C? I thought I was waiting for a 5C NFC, but maybe I've been overlooking the obvious. For some reason it never occured to me that it might work plugged directly into my phone if only it had the right shape. (I have a 5 Nano, which was great until I got a USB-C Macbook and broke several keychain adapters before giving in and buying one of those hubs that stick on one…

I have used the 5C with my Samsung Galaxy note w/o any issues, just plug it in the bottom.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#167
post #148

Does the 5C/Nano work with Android phones with USB-C? I thought I was waiting for a 5C NFC, but maybe I've been overlooking the obvious. For some reason it never occured to me that it might work plugged directly into my phone if only it had the right shape. (I have a 5 Nano, which was great until I got a USB-C Macbook and broke several keychain adapters before giving in and buying one of those hubs that stick on one…

This is what I do. The USB-C one's work on Android just fine but it's a little less intuitive; the YubiAuth app still complains if NFC is disabled and you might have to turn on OTG for the key to be recognised (which auto turns off on some phones after 10 mins).

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#168

Earlier quoted context omitted.

Can you create one that doesn't forward to your phone? Could a US friend create one for you in a new account and hand that account over to you? It's more about sinking that second factor somewhere that can't be redirected and only you can theoretically access by logging into Google Voice. You don't have to forward the messages to your actual phone.

I think each Google Voice number needs a real US phone number, where calls/texts sent to GV Number will be forwarded to.

> print your recovery code and store it in a safe location, and that you set up at least two security keys or authenticator devices. Should you lose access to all two-step verification devic

but this can be configured to not forward the text/voicemail.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#169

Serious question: If Safari doesn't support U2F/FIDO what good will a Lightning based Yubi key do me? To be clear, I'm not knocking the use of these keys. I have Yubi Nano on my laptop and love it.

You can download Chrome, Firefox and Opera from the Apple App Store.

Re: Yubico launches its dual USB-C and Lightning two-factor security key

#170
post #155

I was an early, enthusiastic adopter of Yubikeys at my work. Above and beyond the other issues people have mentioned, though, the one that kills the product for me is the frankly stupid OS integration. The key behaves like “just” a special kind of keyboard which types a long string of gibberish and then hits enter any time you touch the trigger. I can’t tell you how many times I have accidentally bumped the thing and…

You can disable this OTP mode of the YubiKey with either the "Yubikey Manager" or more advanced "Yubikey Personalization Tool" software. It's unrelated to FIDO U2F. It's the first thing I do with any new key as I find it similarly annoying.. I accidentally tapped it once while working in Adobe Lightroom and it triggered a sequence of actions that went on for 30 seconds that I couldn't undo..
Post reply on HN