Live data from Hacker News

Support for U2F security keys

blog.1password.com

31–40 of 164 posts

Re: Support for U2F security keys

#31

Earlier quoted context omitted.

Interesting. If this is the case, I think you have a communications problem. I was under the impression that after 6.0, the only way to get a license was to have your older one grandfathered. I can't find any information about this on your website. All of the options on your product info pages other than "enterprise (email us for a quote)" show monthly subscriptions only. Where can I see product info about the licens…

I agree their website is somewhat confusing, it nudges quite strongly towards purchasing a 1Password subscription. However these pages[1,2] makes quite clear that you can purchase a standalone license even if you're not upgrading: > Or, to purchase a standalone license, click “Need a license? We have those too.” After purchasing your license, add it to 1Password. > Or, to purchase a standalone license, click “Need a…

Aha. I'd advise them to make this clear from the "new user" perspective, rather than just the "upgrade" path, because when I started this job, I set out to purchase a brand new license and was given the impression that it wasn't available anymore.

Edit: I've literally had this belief for years, and I absolutely love their product. I'm the classic case of the user that's already decided to purchase and all they need to do is take my money, but I gave up. Searching produced a forum post where there was a litany of users who were thoroughly confused about the availability of the licensed version, as well. We are clearly not alone.

Re: Support for U2F security keys

#32
post #15
post #3

It appears via the screenshot that you can have multiple 2FA devices, which is great. I love my Yubikey in theory, but in practice I'm only using it for services where I can have a TOTP or SMS 2FA backup method, because I'm not convinced it will always work or be available. Even if having SMS 2FA enabled negates any security benefits of the Yubikey. Thus far it's just Dropbox and Gitlab that I use it for, since they'…

All the services that I have used with U2F support have supported multiple keys. Google, Gitlab, Github, and some others which I forget. They have all worked with Yubico U2F keys and with the Google Titan keys. Pretty convenient way to have two factor authentication. I like the Yubikey 5 Nano as you can leave it plugged into a port in your laptop all the time.

> All the services that I have used with U2F support have supported multiple keys. Google, Gitlab, Github, and some others which I forget.

I've run into a number of services that only allow a single U2F key (it's been a while, so I don't remember the exact ones). Even if they do support multiple U2F keys, how do you handle enrolling both? I keep my backup key offsite, so ideally I could enroll it without physically possessing the device. If I have both in my possession at all times (or even sometimes), I'm at risk of losing both of them.

Re: Support for U2F security keys

#33
post #19
post #8

Earlier quoted context omitted.

I have 3 yubikeys to avoid this problem

How do you manage keeping all the keys "synced" in terms of which services they are registered with. I keep keys in separate locations for safety, but that makes adding all keys to a new account a big pain. This hasn't been a big problem yet because there are so few services that support the keys, but I wonder how people would manage it if it became widespread.

It's a pain, I don't have a good answer.

What I'm going to do personally is only use U2F on my most secure services (email, 1Password itself, GitHub). 1Password with the TOTP stored inside of it should be good enough for the others.

Re: Support for U2F security keys

#34

Earlier quoted context omitted.

Interesting. If this is the case, I think you have a communications problem. I was under the impression that after 6.0, the only way to get a license was to have your older one grandfathered. I can't find any information about this on your website. All of the options on your product info pages other than "enterprise (email us for a quote)" show monthly subscriptions only. Where can I see product info about the licens…

I second this. I actually switched my entire household over to keypass because I was under the impression that I was forced to use the 1password cloud service.

Even if you pay for it as a subscription, you can still create standalone vaults that don't use the cloud sync. I find the cloud service useful for my personal stuff (for sharing purposes) but I keep client info in separate local vaults.

Re: Support for U2F security keys

#35
post #19
post #8

Earlier quoted context omitted.

I have 3 yubikeys to avoid this problem

How do you manage keeping all the keys "synced" in terms of which services they are registered with. I keep keys in separate locations for safety, but that makes adding all keys to a new account a big pain. This hasn't been a big problem yet because there are so few services that support the keys, but I wonder how people would manage it if it became widespread.

For U2F there's nothing to be in sync: each key is added individually, and you don't have to add all of them at once. I.e. if you register the key on your keychain at work, you could later add the backup key in your home vault.

For storing TOTP keys on your YubiKeys, those must be the same, so you probably have to add them at the same time, or take a picture of the QR-code before you complete the registration.

Re: Support for U2F security keys

#36

Got a free YubiKey from Wired. Then I read that mobile is a pain, and that I really need two ... it's sat in my bag now for months, unused. I already use 2FA, and it works good enough - I'm not sold on how this will make my life better, especially on mobile.

Yubico makes a Yubikey with NFC, if you're interested.

https://www.yubico.com/products/yubikey-for-mobile/

Re: Support for U2F security keys

#37
post #16

Got a free YubiKey from Wired. Then I read that mobile is a pain, and that I really need two ... it's sat in my bag now for months, unused. I already use 2FA, and it works good enough - I'm not sold on how this will make my life better, especially on mobile.

The primary purpose of U2F/WebAuthn is to break phishing attacks. Code-based TOTP 2FA, the kind you're probably using now, is already adequate to the task of making sure you're not credential-stuffed.

Autofill of a password manager is a working countermeasure against phishing too: If autofill does not work there is something wrong and you should look closer...

Re: Support for U2F security keys

#38
post #19
post #8

Earlier quoted context omitted.

I have 3 yubikeys to avoid this problem

How do you manage keeping all the keys "synced" in terms of which services they are registered with. I keep keys in separate locations for safety, but that makes adding all keys to a new account a big pain. This hasn't been a big problem yet because there are so few services that support the keys, but I wonder how people would manage it if it became widespread.

This has become a pretty big problem for me. I keep the backup key offsite, and retrieve it every few months to enroll as a backup device with new services. I try to keep a list of services I need to enroll it in, but I've definitely forgotten to do so at times.

Ideally there would be a way to enroll the second device without possessing it, but I'm not sure that's technically possible.

Re: Support for U2F security keys

#39
post #25

I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?

I tried to get mine as future-proof as possible, but I was left with a choice of either getting the Yubikey Neo with NFC or a Yubikey with USB-C.

I went with the Neo, because it supports all of my current devices, and for USB-C future testing, I tested it on my phone with an USB A-C adapter and it worked there as well. I'm a Linux/Android user without any Apple devices, though, so YMMV.

EDIT: Should also mention that I received a free basic Yubikey as a gift for subscribing to Ars Technica about a year ago. USB-to-MicroUSB and USB-to-C adapters worked on that for all of my devices, as well. I feel pretty confident switching to Yubikeys now that I have two and can keep the newish one on my keychain at all times, with the basic one in a secure place at home.

Re: Support for U2F security keys

#40
post #25

I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?

A bluetooth capable U2F device like the Titan.

you can't use that with computers. You have to use a dongle + cable to connect to new macbook pros
Post reply on HN