Live data from Hacker News

YubiKey 4C

yubico.com

241–250 of 266 posts

Re: YubiKey 4C

#241
post #115

Earlier quoted context omitted.

I can confirm that the NFC support works (yubikey neo with a nexus 5x) - but very few applications and sites support it.

I use the NFC Yubikey to store a PGP key, which can then be used with pass [1] + GPG on the desktop, and Password Store + OpenKeychain on Android. Works nicely. And if you choose to also keep the PGP key on the desktop, you don't need to carry the Yubikey. [1] https://www.passwordstore.org

I use this setup, it's fantastic.

Re: YubiKey 4C

#242

Earlier quoted context omitted.

I had a Nano. I'm like 99% sure all the GP would have to do is tie a wire to the metal tab, and then he could bump the other end of the wire with any part of his body.

You're probably right.

We use the nanos heavily at my workplace. I've seen people make a chain out of paperclips when their nearest USB port is too far away (and they can't be bothered to grab an extension cable).

Re: YubiKey 4C

#243

I REALLY wish it were possible to use one of these devices without using your hands. I'm quadriplegic and would love to use one of these to unlock my computer, bank passwords etc etc. But you have to touch a finger to almost all of them to trigger the OTP, or whichever authentication and they happen to be using. I would absolutely love to be able to lock and unlock my Mac without an able-bodied person helping me, bec…

Windows hello might help you. There are laptops that use depth mapping infra red cameras with the native face recognition in windows. Probably the best hands free unlock method.

Re: YubiKey 4C

#244
post #200

Earlier quoted context omitted.

1. enter company you don't work at and steal laptop at lunch hour 2. walk to cafeteria with laptop that looks like any other. let owner watch unlock it for you. 3. profit! 4. optional, return laptop before lunch is over for full stealth.

There are a lot of attacks one can imagine when you have physical access to hardware inside the building. Why not just boot to a thumb drive and install malware?

Because the computer is locked?

Re: YubiKey 4C

#245
post #157

Earlier quoted context omitted.

I think I'm not understanding the problem. I have cloned keys (for backup + two locations), with Yubico Authenticator. Is the problem NFC on iOS or that you don't want to clone your keys?

My problem is that while I can reasonably guarantee that my YubiKey will be near my laptop when I use it, I generally can't guarantee that my YubiKey will be near my phone or tablets when I use them. I also don't really want to keep plugging in a physical key into my phone every time I want to log into, say, American Airlines to check the status of my flight, or into PapaJohns.com every time I want to order a pizza.…

Why would you need two factor auth on a phone? Most phones have fingerprint sensor built in. And you can set up a super secure password that needs to be entered on boot.

Now that I think of it, why is 2fa needed in a laptop with a fingerprint sensor?

Re: YubiKey 4C

#246

Until these things work well with phones, I can't buy into them. I have a U2F key that I use as a shortcut for accessing things like Google's services. But I am sticking to always using either Google Authenticator or SMS, if it's available, as a primary option. When I am looking at a website in bed on my phone, and my YubiKey is in my laptop downstairs, I can't say I am happy that I can't access my account. I think t…

Screw it, let's all get chips embedded in our fingers.

Re: YubiKey 4C

#247

Earlier quoted context omitted.

There are a lot of attacks one can imagine when you have physical access to hardware inside the building. Why not just boot to a thumb drive and install malware?

Because the computer is locked?

If they don't have full disk encryption, booting a mac holding command and R will get you into recovery mode where you can change the root password, or change the boot device to something that simply doesn't care about the login permisions. Pretty much any machine without full disk encryption at rest is vulnerable when you have physical access. And if they do, you can still probably do a lot of damage, without Bumping into someone at lunch with their laptop.

Not saying it's not a real vector, but it's hardly one that would keep me up at night.

Re: YubiKey 4C

#248
post #111

Earlier quoted context omitted.

They do work with phones. I have an iPhone with a Lightning-Camera (USB) adapter and use it all the time.

Unfortunately, not for U2F though

Both the static and OTP modes of Yubikey work for me through this adapter.

Re: YubiKey 4C

#249

Earlier quoted context omitted.

There are a lot of attacks one can imagine when you have physical access to hardware inside the building. Why not just boot to a thumb drive and install malware?

Because the computer is locked?

There have been successful attacks on locked macs via the thunderbolt port.

I'm thinking of one in particular which I can't find at the moment, but I remember seeing a really fantastic video where one guy described in detail how he reverse engineered the mac thunderbolt interface and was able to flash malware bootcode on to it even when locked. Once that malware was installed, it could do pretty much anything, including get encryption keys to your hard drive, intercept all keystrokes, etc.

If anyone has a link to that, please post it here.

Also, there this:

https://news.ycombinator.com/item?id=7123121

Re: YubiKey 4C

#250
post #216
post #84

Earlier quoted context omitted.

Wait – Yubikey is associated with Google? Or did you mean that whatever alternatives people suggest mustn't be associated with Google?

There are some connections. The people who founded it. Google are early investors. Google are also one of the most important costumers. I think that makes it even more secure. Google house lots of people running around with these.

"I think that makes it even more secure."

That reminds me of how for a long time people were saying that encryption influenced and blessed by the NSA must be secure because government agencies were using it and the NSA wouldn't weaken their encryption.

Turns out they did.

Post reply on HN