Live data from Hacker News

FIDO2 security key company publishes results of internal security audit

blog.doyensec.com

21–30 of 64 posts

Re: FIDO2 security key company publishes results of internal security audit

#21
I have two OnlyKeys I backup against the other to handle the lack of ubiquity of FIDO2. So many places are still only using SMS, but as an alternative, have built proprietary, in-app authentication systems that can't be audited. I had a phone break, and I wanted to purchase a new phone online to have it ship when I returned; and I couldn't access my remote work paycheck transfer (in-app), I couldn't log into my bank (SMS + in a different country so not the same SIM), and I couldn't log into the more popular online shopping (SMS).

Auth needs to be able to be decoupled from phones. With the OnlyKey, I've stored the important TOTP keys as well like my email as well as password for my password manager. Being as 'dumb' as they are, I've had it go through the wash still working fine.

Re: FIDO2 security key company publishes results of internal security audit

#22
post #3

Who is this company and why would I buy a key from them instead of Yubico?

Don't know who they are but there's some speculation that Yubico is Crypto AG like.

Not by anyone with half a clue there isn’t.

Re: FIDO2 security key company publishes results of internal security audit

#23

I am probably wrong, but I think Fido2 keys should be ubiquitous. They provide a hardened solution for some security situations, certainly they could be a good 2nd factor or 3rd, and hopefully they could reduce the password madness we have. Yubico appears focused on the enterprise and high end users resulting in higher prices. Solokeys seems more focused on individual users with lower prices. Disclaimer I have two Yu…

Don't get me wrong I love the idea of physical/hardware security; however, isn't the reason it is so effective right now because it is not mainstream?

Re: FIDO2 security key company publishes results of internal security audit

#24

I got a Solokey as part of the Kickstarter and love em. USB-C + NFC in one device. The one thing I'd love out of a security key is the ability to set up a "Twinned Pair". So I can have one key on my keychain that I use everyday and one I keep in my safe in case something happens to the primary. Yes, I know some services support multiple security keys - but setting up two is more work and not all services do support t…

I definitely would like the requirement to allow multiple keys to be a part of the standard. Allowing it at the key level seems dangerous to me, perhaps, in allowing an attacker to perhaps "clone" someone's key that hasn't setup a pair yet, though of course I'm sure there's mitigations for that if it was seriously proposed!

I have two Yubikeys, one in a safe and one on my person. It saved my butt when I lost access to the one on my person for a few days!

Re: FIDO2 security key company publishes results of internal security audit

#25
post #23

I am probably wrong, but I think Fido2 keys should be ubiquitous. They provide a hardened solution for some security situations, certainly they could be a good 2nd factor or 3rd, and hopefully they could reduce the password madness we have. Yubico appears focused on the enterprise and high end users resulting in higher prices. Solokeys seems more focused on individual users with lower prices. Disclaimer I have two Yu…

Don't get me wrong I love the idea of physical/hardware security; however, isn't the reason it is so effective right now because it is not mainstream?

Go on...?

Re: FIDO2 security key company publishes results of internal security audit

#26
post #3

Earlier quoted context omitted.

Don't know who they are but there's some speculation that Yubico is Crypto AG like.

Not by anyone with half a clue there isn’t.

This is such a lame conspiracy theory that me and lawnchair_larry are on the same side of it.

Re: FIDO2 security key company publishes results of internal security audit

#27
post #25
post #23

Earlier quoted context omitted.

Don't get me wrong I love the idea of physical/hardware security; however, isn't the reason it is so effective right now because it is not mainstream?

Go on...?

Having a few vaults with security guards is a great deterrence as the reward is little for the high risk. Having many vaults with security guards draws a bit more attention...

Re: FIDO2 security key company publishes results of internal security audit

#28
Physical hardware seems like a promising replacement for passwords. But is there any real adoption in consumer services right now? The only two services I know that suppport Fido2 are Google and GitHub. Are there any other big services I'm missing here?

Re: FIDO2 security key company publishes results of internal security audit

#29
post #28

Physical hardware seems like a promising replacement for passwords. But is there any real adoption in consumer services right now? The only two services I know that suppport Fido2 are Google and GitHub. Are there any other big services I'm missing here?

Known to me: Bitwarden, Gitea, GitLab.

Also Dropbox, Salesforce, Gandi, Namecheap, and a couple cryptocurrency exchanges, according to https://www.dongleauth.info.

Re: FIDO2 security key company publishes results of internal security audit

#30
post #28

Physical hardware seems like a promising replacement for passwords. But is there any real adoption in consumer services right now? The only two services I know that suppport Fido2 are Google and GitHub. Are there any other big services I'm missing here?

Microsoft supports passwordless login (you can try it out on outlook.com — some ppl refer to this as username less).

Dropbox is also an early adopter.

Plus you have all the u2f that are back compat, including facebook, twitter, aws, gitlab... (I may have confuse some u2f that already moved to webauthn, if so, sorry).

Considering that webauthn was standardized last March and that ios still has no in-app support, that’s a pretty good start, I think.

Post reply on HN