How to Yubikey
171–180 of 186 posts
Re: How to Yubikey
#172Re: How to Yubikey
#173Re: How to Yubikey
#174Re: How to Yubikey
#175Re: How to Yubikey
#176Earlier quoted context omitted.
I actually considered that setup but decided against it. The thing is, if I did this, I would eventually succumb to convenience and would plug the key into the machine at all times . But that defeats the purpose: if a thief steals my computer they can just tap the key rather than know my password to unlock my disk.
You normally have and you should have a fido2 pin, which is just a password. A thief would need your laptop, your security key, and the fido2 pin. Here is an article (from yubico) about fido2 pins: https://support.yubico.com/hc/en-us/articles/4402836718866-U...
Re: How to Yubikey
#177Earlier quoted context omitted.
Not really keys, but hardware wallets like Trezor or Ledger can do a lot of this for ~twice the price.
Hardware wallet authentication is really one of the 'web3' technologies that just works and we could be deploying everywhere right now. It's miles better than yubikey spitting out a static password, has plugins for every major browser and mobile device platform, can do identity verification without specific site account setup, and of course the whole pile of (optional) web3 things with crypto.
Cryptocurrency wallets are horrible for normal security features that do not involve blockchains.
Re: How to Yubikey
#178Earlier quoted context omitted.
Hardware wallet authentication is really one of the 'web3' technologies that just works and we could be deploying everywhere right now. It's miles better than yubikey spitting out a static password, has plugins for every major browser and mobile device platform, can do identity verification without specific site account setup, and of course the whole pile of (optional) web3 things with crypto.
Counterpoint: it’s miles worse than FIDO/WebAuthn, which most hard keys and modern OSes support. Asking users to install a browser plugin is a disaster waiting to happen for most users. Phishing of cryptocurrency hardware wallets happens all the time, but it is impossible to phish a Passkey. The reason a browser plugin is required is because these devices are made to transact on a blockchain, rather than open APIs in…
Re: How to Yubikey
#179Earlier quoted context omitted.
Counterpoint: it’s miles worse than FIDO/WebAuthn, which most hard keys and modern OSes support. Asking users to install a browser plugin is a disaster waiting to happen for most users. Phishing of cryptocurrency hardware wallets happens all the time, but it is impossible to phish a Passkey. The reason a browser plugin is required is because these devices are made to transact on a blockchain, rather than open APIs in…
I think the fact that cryptocurrency wallets with millions of dollars still exist and are protected by these wallets is evidence that security is manageable. Proof is in the pudding.
There are so many UX reasons why you would never want to conflate a login token with a key that can mathematically and instantaneously eviscerate your life savings. But to put it simply; there’s no way anyone’s grandma can use this system, wherein with something like browser Passkeys she has a chance.
Re: How to Yubikey
#180Reminder: Yubico doesn't have a monopoly on security keys. Make sure your software/tutorials support the open-source alternatives like OnlyKey and NitroKey.
The backup functionality (which requires encryption password entry on a computer, i.e. not the device itself) looks especially concerning.