Strong advise anyone considering putting one of these on their keychains to consider otherwise. The actual connector of my usb-c version has warped in my pocket over time and it’s now not recognised.
Yubico launches its dual USB-C and Lightning two-factor security key
171–178 of 178 posts
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#172Strong advise anyone considering putting one of these on their keychains to consider otherwise. The actual connector of my usb-c version has warped in my pocket over time and it’s now not recognised.
For a pretty critical device, the USB-C version is rubbish.
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#173Earlier quoted context omitted.
I think I get what you are trying to express, but rather than "it authenticates the site to you", I think that should be phrased "it prevents you from authenticating at a site pretending to be some other site. evil.com can still claim to be mysite.com and trick users into using their security key there, no? It would presumably have to trick the user into "registering again" since there is no valid key handle for FIDO…
Suppose the key allows mysite.com to let you see your emails, send more emails, and send money to people, etc. Basically mysite.com let's you see and do interesting things after you've authed. Even if evil.com gets you to register and present your key, they cannot forward it to mysite.com. Even if they go to all the trouble to completely mitm you and the site looks identical to mysite.com, they cannot get the emails…
I'd just be careful about overly relying on this property or calling it anything like mutual authentication:
If an attacker can make an educated guess about a user's account contents, they could still convince them to provide additional personal information once they let their guard down after authenticating.
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#174Earlier quoted context omitted.
In addition to what you're saying, I also would like to register multiple keys to services such that any one would work, not that both are required. I don't need them to be nuclear keys... I want a backup key stored in a safe and one on my keychain. This seems to be very uncommon amongst service providers.
I’d say this is actually the most common. I’m not aware of any websites that allow >1 U2F/FIDO key in the configuration where you need to use all-of-them to log in. Sites either only support 1 key, or support multiple keys and you need 1 of them to log in.
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#175Earlier quoted context omitted.
Is there no lightning to USB A adapter? Seems a bit wasteful to buy another key for a currently very limited ability in iOS.
While limited today, there are a bunch of applications in beta testing that leverage the key. I personally have a small keychain usb-c to A adapter that I use with my Yubikey Neo. I guess all in they decided a Lightning and USB A option wasn't as smart given most mobile devices are Lightning or USBC moving forward.
I think they can actually reduce their offerings to two:
* USB-C and USB-A
* USB-C and Lightning
NFC on both variants.
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#176I actually had the chance to try out a prototype at Blackhat. I was actually able to have the USB-C portion recognized on my Android Phone (via the USB port), and it was recognized in Firefox and lsusb (though for some reason I was unable to register it, and I has the u2f enabled in about:config). I am tempted to buy it to see if I could get it to work on my phone, I would much rather have the USB-C work on my phone…
Any usb-c key should work on Android. Firefox has been recently updated to support webauthn, so you no longer have to turn u2f on. Note that some sites, like Google, only allow you to register the key on Chrome, but then you can use it on Firefox too.
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#177That sounds nice. But while using U2F/FIDO for a few years (with two HyperFIDOs, one for "daily" use attached to my key-chain, the other as a backup in a safe), I found the most common problem was that websites/services don't tread these keys as first class citizens. For example GitHub: I have my two keys setup there, but I can't opt-out of SMS authentication. If I knew I could use my keys at more services, I would a…
Last year I got the Google Titan security keys and connected it with all of my work + personal accounts that support it. The #1 weakness is the simple fact that many services don't allow you to disable alternate forms of 2fa. Github is an example, you can always trigger the fallback SMS 2fa code. Dashlane is another example (and arguably the most important). It's impossible to make your security key the only form of…
TOTP is secure, unlike SMS 2FA.
Re: Yubico launches its dual USB-C and Lightning two-factor security key
#178Earlier quoted context omitted.
The NEO is a Yubikey v3. It supports NFC. v3 is the last FOSS one, but it does not support FIDO2. If you want a YubiKey with NFC which supports FIDO2, you need a YubiKey 5 (NFC version). Or a Solo with NFC (the Solo support FIDO2 and is FOSS). I happen to have one of the InCharge chargers as keychain [1] and what is interesting is that it is 3 chargers in one: one's always USB-A, other one is either USB-C or microUSB…
In my experience too with testing the NEO, they're just not as reliable to work with compared to the later models (both over NFC and USB). I believe the NEO was the first to bring in new features for the Yubikey, and the kinks weren't all ironed out yet. If you have a NEO still, I'd recommend at least upgrading to a 4 if you can.