Live data from Hacker News

YubiKey 4C

yubico.com

261–266 of 266 posts

Re: YubiKey 4C

#261

Earlier quoted context omitted.

In my opinion it's not worth the effort (and certainly not $50). It makes marginally +X harder to exploit yet marginally +X inconvenient to use = typical security through obscurity.

You've lost me at "security through obscurity".

My bad, it's not what classic "through obscurity" means. Instead I meant something that makes exploitation more "obscure" (you need to be prepared to hijack a server vs simply leak the key).

Re: YubiKey 4C

#262
post #200

Earlier quoted context omitted.

1. enter company you don't work at and steal laptop at lunch hour 2. walk to cafeteria with laptop that looks like any other. let owner watch unlock it for you. 3. profit! 4. optional, return laptop before lunch is over for full stealth.

Worth noting that the watch alerts that it has been used to unlock the laptop. Doesn't prevent the action, but does prevent "stealth mode unlock"

only if it is reported.

Most people will just ignore it and call a fluke. Just like everyone does when their servers signatures changes. everyone just save the new key and type their passwords away ;)

Re: YubiKey 4C

#263
post #208

Earlier quoted context omitted.

Yes. You have to check out the PIV module. It can even be used as a CA. https://developers.yubico.com/PIV/Guides/ There are a number of tools you can install yubico-piv-manager/yubico-piv-tool but check the guides. I had some problems with this, somehow I could not add the key to ssh-agent, but that was related to the ssh-agent, not sure its a general problem. Note, this does only support 2k keys. If you use the GPG…

Thank you, this is the best guide I've seen so far. It's much simpler to install and use. However, like you, I'm having some problems. Adding the key to the ssh-agent asks for a PKCS password and always comes back with "agent refused cooperation". I also can't log in to a host that has that SSH key, but maybe that's because I have too many keys loaded... EDIT: Never mind, it works perfectly, thanks!

This is the issue I had. I can access the key directly from the file but not add it.

How did you solve it?

Re: YubiKey 4C

#264
post #263

Earlier quoted context omitted.

Thank you, this is the best guide I've seen so far. It's much simpler to install and use. However, like you, I'm having some problems. Adding the key to the ssh-agent asks for a PKCS password and always comes back with "agent refused cooperation". I also can't log in to a host that has that SSH key, but maybe that's because I have too many keys loaded... EDIT: Never mind, it works perfectly, thanks!

This is the issue I had. I can access the key directly from the file but not add it. How did you solve it?

This is a whole post, but basically, there are multiple SSH agents. ssh-agent supports the card and ed25519 keys, but doesn't support persisting keys across reboots. Gnome keyring supports persisting keys, but no card or ed25519 (AFAIK). gpg-agent supports persisting keys and ed25519, but no card.

Unfortunately, there's no perfect solution, so I just added an alias "yubissh" to include the library in the command line :(

Re: YubiKey 4C

#265
post #233

Earlier quoted context omitted.

Actually they can. Features are being added, for example using iphone's nfc chip as a work pass.

cite? first I've heard of it.

I can't cite it right now, but I can ask iOS devs from our mobile team to provide sources on that. I've been told it was recently added to the API.

Re: YubiKey 4C

#266
hi,i'm Brian i had my friend help me hack my ex's email, facebook, whatsapp,and his phone cause i suspected he was cheating. all he asked for was a his phone number. he's email is (hotcyberlord425@gmail.com)..IF u need help tell him Brian referred you to him and he'll help. Am sure his going to help you do it, good luck
Post reply on HN