Live data from Hacker News

Yubico and Microsoft Introduce Passwordless Login

yubico.com

41–50 of 218 posts

Re: Yubico and Microsoft Introduce Passwordless Login

#41
post #40
post #17

Okay, so I have two Yubico U2F keys and two other U2F keys so far. I don't think I'll buy a fifth and sixth anytime soon. But hopefully U2F will actually work in non-Chrome browsers in the near future.

It already works in Firefox (behind a flag), but sadly some websites explicitly target Chrome...

Exactly. In practice it doesn't work. I have a few web sites where I'm using U2F, none of those works with Firefox.

Re: Yubico and Microsoft Introduce Passwordless Login

#42
post #15
post #9

Two things - is there really need for them to be this large? They also look vulnerable? Maybe its just the look, but the blue one looks like it won't survive proper stress test... And second thing - is exposing connector safe against mechanical damage? Will it withstand constantly being scratched by keys?

There is the "nano" version available which is a lot smaller than the one advertised. The ones that I own have held up just fine for the past year on my keychain. https://www.yubico.com/product/yubikey-4-series/#yubikey-4-n...

Do previous YubiKeys support FIDO2? From the post, I assume you need one of the new ones.

Re: Yubico and Microsoft Introduce Passwordless Login

#43
post #40
post #17

Okay, so I have two Yubico U2F keys and two other U2F keys so far. I don't think I'll buy a fifth and sixth anytime soon. But hopefully U2F will actually work in non-Chrome browsers in the near future.

It already works in Firefox (behind a flag), but sadly some websites explicitly target Chrome...

FF traditionally required a plugin, I think native support is recent?

Re: Yubico and Microsoft Introduce Passwordless Login

#44
post #15

Earlier quoted context omitted.

There is the "nano" version available which is a lot smaller than the one advertised. The ones that I own have held up just fine for the past year on my keychain. https://www.yubico.com/product/yubikey-4-series/#yubikey-4-n...

This size is much better, but I assume it lacks the "touch" protection against remote attacks, like the other ones? I still wonder about the exposed connector - what its durability. After all, I would like for such a tool to serve me for years fault-free.

They’re pretty sturdy. I’ve used my keychain version to pry off beer caps, and it’s gotten some scratches but works fine. The touch sensor is kind of annoying but it does work.

Re: Yubico and Microsoft Introduce Passwordless Login

#45
post #17

Okay, so I have two Yubico U2F keys and two other U2F keys so far. I don't think I'll buy a fifth and sixth anytime soon. But hopefully U2F will actually work in non-Chrome browsers in the near future.

> But hopefully U2F will actually work in non-Chrome browsers in the near future.

I would guess you're referring to being able to log in to gmail (or anything in G Suite) with U2F from Firefox.

U2F is already available in the most recent version. See "security.webauth.*" keys in about:config. It just won't work with Google, at least not yet. Google's implementation predates webauth by a pretty fair margin, and from what I have learned, is different in small but important ways from the standard.

So we have a situation that drips irony: we have a U2F standard, usable via a standard authentication mechanism - and incompatible with the very web property that drove the concerted push for the technology's adoption.

Re: Yubico and Microsoft Introduce Passwordless Login

#46
post #45
post #17

Okay, so I have two Yubico U2F keys and two other U2F keys so far. I don't think I'll buy a fifth and sixth anytime soon. But hopefully U2F will actually work in non-Chrome browsers in the near future.

> But hopefully U2F will actually work in non-Chrome browsers in the near future. I would guess you're referring to being able to log in to gmail (or anything in G Suite) with U2F from Firefox. U2F is already available in the most recent version. See "security.webauth.*" keys in about:config. It just won't work with Google, at least not yet. Google's implementation predates webauth by a pretty fair margin, and from w…

It’s almost as if we shouldn’t deviate from standards just to get features out of the door faster

Re: Yubico and Microsoft Introduce Passwordless Login

#47
post #10

Correct me if I am wrong, but passwordless login is a single-factor authentication and less secure than MFA. Depending on whenever hardware key is more or less secure than the password, the mass adoption of this could make things LESS secure.

I would expect things to be more secure in many cases. People are pretty good at keeping physical items somewhat safe and notice when they’re gone. Yubikeys cannot easily be cloned. The password cannot be attacked remotely. 2FA is certainly safer, though.

The standard in high-assurance applications is to present a PIN to the hardware token before it can be used, ideally through an out-of-band keypad.

In this context, it would be reasonable to have the Yubikey require a PIN entry from the computer. You could use the same PIN for all sites because it stays local; the relying party never handles it, only the Yubikey.

Re: Yubico and Microsoft Introduce Passwordless Login

#48
post #31

Earlier quoted context omitted.

I doubt that. Friends or family can't read your mind, but they can steal your physical key. People putting pins on their phones or password on their laptop are not afraid of being pirated. This is a vague, abstract threat to them. Becoming part of a botnet is really not important to them, and they getting their credit card stolen from the web is really not credible enough for non tech saavy user. What they are afraid…

Anyone in the world could crack your password. (Well, any of 2.5 billion people with an internet connection.) Requiring a physical key instead cuts the attack surface down quite a bit. If you can secure your car and house keys, you can secure this.

I think you should elaborate on the specific threat model you're describing. Are you assuming a dumped database? Or are you talking about a brute force against an online service?

Re: Yubico and Microsoft Introduce Passwordless Login

#49
post #16

Earlier quoted context omitted.

That is confirmed in the "How does this work?" section. Your concern is addressed in the "Why is this important?" section. The key is definitely more secure against cracking than a password. It is more vulnerable to being physically stolen, but for most people, that is a lower risk.

I doubt that. Friends or family can't read your mind, but they can steal your physical key. People putting pins on their phones or password on their laptop are not afraid of being pirated. This is a vague, abstract threat to them. Becoming part of a botnet is really not important to them, and they getting their credit card stolen from the web is really not credible enough for non tech saavy user. What they are afraid…

Friends and family can also steal your credit card, but this is not where the majority of credit card theft comes from.

Your example of people leaving the key with the laptop is a good example of one of the potential flaws, but just like if your credit card gets lost or stolen, you report it and it becomes unusable.

I agree that there is room for 2FA, but this is also surely preferable to the current system.

Re: Yubico and Microsoft Introduce Passwordless Login

#50
post #37
post #26

Earlier quoted context omitted.

Except that passwords at least protect you if your hardware key is stolen. Using just a hardware key seems similarly risky to just using a password.

So in this case, arent the two factors a) physical possession of desktop/laptop and b) the Yubikey ? How likely is it you'll lose both if you keep your keyring with you?

Not sure reading the article why would I need the computer. The way I read it, you enter the key to any computer and it logs in to the account of the key owner. Am I wrong?
Post reply on HN