Live data from Hacker News

Strengthening 2-Step Verification with Security Key

googleonlinesecurity.blogspot.com

21–30 of 150 posts

Re: Strengthening 2-Step Verification with Security Key

#21
post #19

With more interaction online moving to smartphones and tablets, what do we do instead of USB hardware keys like these?

Wearables with BTLE.

Bluetooth has too long range. That's why it was never a good idea for Apple to adopt it for payments either, despite all the cheering for it when BLE came to the iPhone. I'd rather these only work with NFC (you know, like Apple Pay). Although I wouldn't mind the BLE option too for things like opening the garage door. But for anything else where you're at close range anyway, it should be NFC by default.

Re: Strengthening 2-Step Verification with Security Key

#22
post #15

This seems to me to be a bit of a narrow market. At the upper end of secure machines, USB ports will be physically disabled. And if you're not hyper security conscious, you're not going to bother with a physical key. So with this, you need to be somewhat paranoid, but not totally paranoid.

I think I might prefer this to the current mobile authentication. I often find that the times I need to log in to somebody elses computer, is also when I don't have my phone around. A small usb-something which fits in my wallet would be a nice back-up.

Re: Strengthening 2-Step Verification with Security Key

#24
post #12

Security Key does not work on browsers other than Chrome. Well that's a bummer. Doesn't mean it can't be useful in some settings, though.

Also this though:

> Security Key and Chrome incorporate the open Universal 2nd Factor (U2F) protocol from the FIDO Alliance, so other websites with account login systems can get FIDO U2F working in Chrome today. It’s our hope that other browsers will add FIDO U2F support, too.

Re: Strengthening 2-Step Verification with Security Key

#25
post #23

How does the challenge get from the web browser out to the USB device? I've spent some time looking for a specification, but haven't managed to find the answer to this question.

The device probably registers as a USB keyboard, and it "types out" the 2-factor code when you tap it.

Re: Strengthening 2-Step Verification with Security Key

#28
post #25
post #23

How does the challenge get from the web browser out to the USB device? I've spent some time looking for a specification, but haven't managed to find the answer to this question.

The device probably registers as a USB keyboard, and it "types out" the 2-factor code when you tap it.

[deleted]

Re: Strengthening 2-Step Verification with Security Key

#29
post #23

How does the challenge get from the web browser out to the USB device? I've spent some time looking for a specification, but haven't managed to find the answer to this question.

It uses HID. The specs are here: https://fidoalliance.org/specifications/download

Re: Strengthening 2-Step Verification with Security Key

#30
post #15

This seems to me to be a bit of a narrow market. At the upper end of secure machines, USB ports will be physically disabled. And if you're not hyper security conscious, you're not going to bother with a physical key. So with this, you need to be somewhat paranoid, but not totally paranoid.

> At the upper end of secure machines, USB ports will be physically disabled. And if you're not hyper security conscious, you're not going to bother with a physical key.

The reason that "upper end of secure machines" have disabled USB ports is because they are organization-owned machines that are issued to untrusted employees (often in organizations where all employees are untrusted in the relevant sense). But in the case of first-party machines (e.g., personally owned machines) where the user is similarly security-conscious, that factor doesn't exist. So, really, all you need to be is a security-conscious individual that uses your own computer for things where you have security concerns. (Or, as an organization, be one where the threat profile you concerned about addressing is more external than internal.)

Post reply on HN