Until these things work well with phones, I can't buy into them. I have a U2F key that I use as a shortcut for accessing things like Google's services. But I am sticking to always using either Google Authenticator or SMS, if it's available, as a primary option. When I am looking at a website in bed on my phone, and my YubiKey is in my laptop downstairs, I can't say I am happy that I can't access my account. I think t…
I think I'm not understanding the problem. I have cloned keys (for backup + two locations), with Yubico Authenticator. Is the problem NFC on iOS or that you don't want to clone your keys?
YubiKey 4C
171–180 of 266 posts
Re: YubiKey 4C
#172Earlier quoted context omitted.
Why not run an operating system that does let you use accessibility software at the login screen?
My friend, if you could find me an operating system that can do that, and then once inside the OS enable me to use every single function of the operating system like an able-bodied person in the way the Apple's does I'll give you a small prize. I would absolutely love to use free and open source software for both my operating system and everything else, but only Apple provides an experience for people with profound d…
https://wiki.gnome.org/Accessibility
Fedora or Debian is probably the easiest way to get a GNOME desktop these days.
Re: YubiKey 4C
#173Earlier quoted context omitted.
>It renders your point about source code moot though, doesn't it. Security is ultimately the art of trust propagation. I don't see how that follows. If I can audit the source code and confirm that the same code is running on the device, the weak link is reduced to my ability to aduit it (combined with everyone else who's auditing it as well and might publish their findings). >The most famous discourse here is the "un…
> the weak link is reduced to my ability to aduit it (combined with everyone else who's auditing it as well and might publish their findings). And if the hardware itself has microcode that overrides your code? > but this is ridiculous. Do you really think that the Yubikey folks have backdoored my copy of gcc? Actually, I think the first and foremest threat would be, "Could someone insert a yubikey into a malicious de…
Hard to defend against this, but it can be helped by using well understood architectures and letting us confirm that the microcode being run is the same microcode that the upstream CPU vendors are publishing.
>Actually, I think the first and foremest threat would be, "Could someone insert a yubikey into a malicious device that changed its behavior such that it now leaks information and does not provide actual security."
I'm not going to keep entertaining this discussion if you keep disregarding everything I've already said. I've already said I'm only asking for read-only access. In any case, defending against physical compromise is close to impossible anyway.
Re: YubiKey 4C
#174Earlier quoted context omitted.
They have a NFC yubikey available, and most new phones work with USB-C (which this one has)
I can confirm that the NFC support works (yubikey neo with a nexus 5x) - but very few applications and sites support it.
Re: YubiKey 4C
#175Earlier quoted context omitted.
> the weak link is reduced to my ability to aduit it (combined with everyone else who's auditing it as well and might publish their findings). And if the hardware itself has microcode that overrides your code? > but this is ridiculous. Do you really think that the Yubikey folks have backdoored my copy of gcc? Actually, I think the first and foremest threat would be, "Could someone insert a yubikey into a malicious de…
>And if the hardware itself has microcode that overrides your code? Hard to defend against this, but it can be helped by using well understood architectures and letting us confirm that the microcode being run is the same microcode that the upstream CPU vendors are publishing. >Actually, I think the first and foremest threat would be, "Could someone insert a yubikey into a malicious device that changed its behavior su…
And I've addressed that.
> In any case, defending against physical compromise is close to impossible anyway.
This is a non-statement. I think your religion is getting in the way of further discussion. Goodbye.
Re: YubiKey 4C
#176Earlier quoted context omitted.
I think I'm not understanding the problem. I have cloned keys (for backup + two locations), with Yubico Authenticator. Is the problem NFC on iOS or that you don't want to clone your keys?
How do you clone a YubiKey? I thought the whole point of having a hardware token in the first place was that it's _not_ easily copied?
It's a one-time write of a seed at device set-up time. It's not an exact clone, but will give the same response to certain challenges.
https://www.yubico.com/support/knowledge-base/categories/art...
https://www.yubico.com/products/services-software/personaliz...
> I thought the whole point of having a hardware token in the first place was that it's _not_ easily copied?
The process generally requires the person personalizing the key to intend to make two (or more) from the beginning of the process. Otherwise, the secret bits that must be entered into the other device to allow one's 2nd Yubikey to generate the same responses to the same challenges will be lost...
Re: YubiKey 4C
#177Why are Yubikeys so expensive? I have one and use them but the price always gets in the way of having more.
Re: YubiKey 4C
#178Earlier quoted context omitted.
Why not run an operating system that does let you use accessibility software at the login screen?
Does Windows 10 let you use accessibility software on the login screen?
Re: YubiKey 4C
#179Earlier quoted context omitted.
My friend, if you could find me an operating system that can do that, and then once inside the OS enable me to use every single function of the operating system like an able-bodied person in the way the Apple's does I'll give you a small prize. I would absolutely love to use free and open source software for both my operating system and everything else, but only Apple provides an experience for people with profound d…
Sounds like you might have tried this already, but GNOME has had a history of working on accessibility, and I think they're quite open to bugs in case something is broken. How well it works in practice, I don't know, though: https://wiki.gnome.org/Accessibility Fedora or Debian is probably the easiest way to get a GNOME desktop these days.
I mean I'm obviously going to try and change the state of accessibility and Linux by submitting bug reports and getting involved, but it's a long slow process and in the meantime I need a computer that works.
Re: YubiKey 4C
#180Remember that closed source security-related products are a complete joke and you should spend your money somewhere else.
Unless you physically inspect each and every device (since they could easily run multiple lots) your faith is in the fabrication of all of the ICs used in the design. Not to mention that the computer you stick these into suffers from the same problem. On the theoretical side, all of the math which this is based upon is probably taken by most people on a faith basis. There is a lot of faith to go around. It just depends where you draw the line.