Live data from Hacker News

Yubico is merging with ACQ Bure and intends to go public

yubico.com

161–170 of 222 posts

Re: Yubico is merging with ACQ Bure and intends to go public

#161

I was a big fan of Yubikey (I have 3) until fewer and fewer services supported them, instead switching to authenticator apps. Now I have zero hard tokens, but still four authenticator apps: Google + 3 for banking services that use their own. The biggest killer was the fact that Yubikey NFC is so awful. I worked with tech support repeatedly, even bought two new keys, and it almost never worked right.

Services support Yubikeys through U2F / WebAuthn, not anything Yubikey-specific, right? If you're using services that don't support that, I take it the apps you do use are using TOTP?

This works with desktop / laptop where you can attach the key over USB.

On mobile, if it works at all, it should be NFC.

Re: Yubico is merging with ACQ Bure and intends to go public

#162

I'm curious how Apple Passkeys will affect the Yubico business. Competition for U2F products may increase drastically as consumers begin adopting it. This may be prescient timing to go public for Yubico.

Probably not at all? Yubico is one of two brands that Apple recommends for securing your iCloud account.

The keys in our phone and our computers are going to handle a majority of the use cases that currently rely on yubico.

We use them at work, but they aren't fundamentally more secure than the what's built into the computer.

Re: Yubico is merging with ACQ Bure and intends to go public

#163
post #92

Earlier quoted context omitted.

I'm not sure what your argument is. Sophisticated investors don't invest in obvious scams. That's tautologically true. Does that mean we should just watch and do nothing while people get scammed? The thing is, nobody is born sophisticated and there are many ways to get hurt in financial markets in the absence of scams even if you're intelligent and do your homework. You mention index trackers, but they are no silver…

> Sophisticated investors don't invest in obvious scams. That's tautologically true. Does that mean we should just watch and do nothing while people get scammed? Imagine I buy a chainsaw which is clearly labelled as something that can cut your hands off, it's widely known and obvious to everyone that chainsaws can cut your hands off very easily, not just in the specialist financial press but also on comedy shows and…

40% of the US workforce has a 401k

It's like giving 40% of the adult population a chainsaw that they have to use if they want to retire at a reasonable age. The outcome is predictable and they would be wise to invest in a prosthetics company.

Re: Yubico is merging with ACQ Bure and intends to go public

#164
post #96

Earlier quoted context omitted.

Cross key syncing service. You plug both yubikeys in. Authenticate on both keys using the tool and then you're able to transfer/backup. Corporate management offerings around Yubikeys, inventories, call back home to renew an expiry if the yubikey itself when touched should give out the information. Trust me, if Yubikey hires me and goes IPO it is all downhill but the company will make a boatload more money. Every comp…

> Cross key syncing service. Can’t work with FIDO/U2F, I’m afraid. The protocol works a little differently than most people expect, which is what allows the hardware token to “store” an unlimited number of auth credentials. What really happens at auth time is that the server (the one you are trying to authenticate to) sends a crypto package including the challenge and a key used to sign the challenge to the token. (T…

I've read about how some folks are using FIDO apps on devices like the Ledger Nano, designed to be crypto currency wallets. These allow the (FIDO) device identity to be exported and later restored onto a new device from the same product line. As I understand it, the experience would be a bit more like restoring a passkey on a new phone, but using a locally secured backup rather than a cloud vendor.

Since reading about that, I've wondered if the relying party in FIDO could or should know the difference. Would this entire product line get flagged in some FIDO registry as having exportable keys? If you really cared, it seems you would need to consider this a static property of the authenticator, whether or not a particular user has decided to make use of the export feature on their device.

Worse, as a software-defined feature, do you get any guarantees at all? Do they do some kind of secure-boot chain so that the FIDO app gets access to a manufacturer key and some other lower quality app cannot be installed to spoof the same authenticator solution?

On the other hand, those devices could be more secure in some practical sense than a Yubikey. They have a display and can show context during an authentication challenge, to reduce the chance that a user is confused about which relying part is asking for the next button press. There is also potential for secure entry of a PIN factor without trusting the host computer to relay this information.

Re: Yubico is merging with ACQ Bure and intends to go public

#166

Earlier quoted context omitted.

Would you (or do you) invest in that company over a different one whose share prices appreciate by a greater amount? Would you accept less compensation if your employer cannot keep up with competitors?

I would stop buying from a company that "decides to go public" (for me, it's just code for "we're now OK with whittling our product's quality to make profits for some people that have found a captive market").

Yes, I tend to do this as well, for the same reason. Also, equivalently, when companies get purchased by public companies, holding companies, investment companies, etc.

Re: Yubico is merging with ACQ Bure and intends to go public

#167

Earlier quoted context omitted.

How would that model work considering the key is a piece of hardware, built to implement an open standard (at least for the U2F mode)? There's no "key phone home" phase in U2F. Also, though I would miss yubikeys if they went under like this, in practice I could switch to google titan or something else and it wouldn't be the end of the world.

The current keys will of course work as before. It is more that their new offerings might change this model all together by tying authentication of the key into some cloud service requiring non-standard drivers. Probably unfounded fears as this would make the keys less attractive to their user base. Yes, there are competitors. But I really don't want to be reliant on Google as a company. I guess Solo Keys and Nitro K…

> I really feel Yubico has a great reputation as far as hardware token companies go.

They do. Or did. With this move, though, the "reputation score" has to reset and be considered neutral until we see what the new behavior will be.

Re: Yubico is merging with ACQ Bure and intends to go public

#168
post #8

Time for an open source u2f token.

Well an interesting new approach to security tokens just launched: the tillitis tkey[1]. It has open source hardware and software. Unlike other security tokens that are based around storing your key where it can't be read, the tillitis tkey doesn't have any persistent storage and instead calculates your private key by hashing the program you've loaded onto the key, a user-supplied secret, and a per-device random secr…

I like the idea, but I'm worried about the FPGA being programmed to exfiltrate the secrets and re-flashed to the original program. With the Yubikey, it's mostly guaranteed that the device key remains on the device. Are there safeguards against this?

Re: Yubico is merging with ACQ Bure and intends to go public

#169

The problem with going public is that performance is now measured quarterly. This incentivizes mortgaging the long-term health of the company for short-term gains. Brand loyalty and trust become assets that can be profitably liquidated by diluting the quality of products and services. By the time customers catch on and the company falters, the investors/owners that profited financially, and managers that profited on…

> The problem with going public is that performance is now measured quarterly. Depends on ownership. When the insiders still own 80% (or control that much through super-voting shares), the minority shareholders’ interests (often but not always short-term) may still be ignored.

The market now measures performance regardless of ownership. Just because they retain a huge percentage of shares, or controlling interest, doesn't mean they'll accept massive declines in market value.

Re: Yubico is merging with ACQ Bure and intends to go public

#170

Earlier quoted context omitted.

> The problem with going public is that performance is now measured quarterly. The company I work for did not IPO yet either, and we still do performance reviews every quarter. So idk if going public matters much in that regard.

who defines your quarterly goals as a private company?

Or more importantly, how are you goals measured after the quarter? Public markets don't take and mitigating factors into consideration when your financials tank the way a private company does.
Post reply on HN