Live data from Hacker News

Using a Yubikey as a touchless, magic unlock key for Linux

kliu.io

41–50 of 74 posts

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#41
A permanently attached Yubikey is not worse than a password alone, and is still superior to SMS 2FA. It still requires that an attacker know both your password and have physical possession of your machine. For the vast majority of users, this is sufficient protection from the threats that they face. The chance that someone both knows your password and is close enough to steal your yubikey is incredibly unlikely.

If you’re the kind of person liable to get personally targeted for nation state level attacks, then you definitely are going to want to unplug your yubikey and keep it on your person. For the rest of us, a hardware 2FA token is enough to protect against a sim swap attack, which is probably enough.

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#42
post #37

Earlier quoted context omitted.

Honestly the threat of someone cloning the key is so minor that a USB stick is probably enough. If someone goes through the effort to make fake a USB stick with the right hardware ids then I've got way bigger problems.

If you are talking about a U2F usb stick I agree with you (I put "incredibly hard" instead of "impossible" there so that I don't get counterarguments with people reading memory with electron microscopes or similar). If you are talking plain USB mass storage for keys I disagree.

For most of us, the inability for the key to be duplicated remotely is the primary design criteria, as most of us need to defend against low to moderate remote attacks (which is exactly SMS 2FA is bad). You have to be an incredibly high value target before "my opponents are willing to send people to try and steal my 2FA token from my person and clone it" is a probable risk. At that point you better be using all kinds of special equipment and techniques, as a Yubikey alone probably isn't enough.

That being said, it's incredibly unlikely that someone would ever sell mass storage based USB credentials because:

1. Security products are marketed based on surviving the worst case scenarios. Nobody would buy a U2F token that is "good enough for the threats you probably face".

2. By the time you've hardened any USB device from remote cloning, you're probably already done most of the work to harden it against local cloning. Might as well complete the last bits necessary in order to get the marketing benefits from point 1.

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#43

Earlier quoted context omitted.

If you are talking about a U2F usb stick I agree with you (I put "incredibly hard" instead of "impossible" there so that I don't get counterarguments with people reading memory with electron microscopes or similar). If you are talking plain USB mass storage for keys I disagree.

For most of us, the inability for the key to be duplicated remotely is the primary design criteria, as most of us need to defend against low to moderate remote attacks (which is exactly SMS 2FA is bad). You have to be an incredibly high value target before "my opponents are willing to send people to try and steal my 2FA token from my person and clone it" is a probable risk. At that point you better be using all kinds…

From what I can read we don't disagree about anything

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#44

Earlier quoted context omitted.

For most of us, the inability for the key to be duplicated remotely is the primary design criteria, as most of us need to defend against low to moderate remote attacks (which is exactly SMS 2FA is bad). You have to be an incredibly high value target before "my opponents are willing to send people to try and steal my 2FA token from my person and clone it" is a probable risk. At that point you better be using all kinds…

From what I can read we don't disagree about anything

[deleted]

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#46

A permanently attached Yubikey is not worse than a password alone, and is still superior to SMS 2FA. It still requires that an attacker know both your password and have physical possession of your machine. For the vast majority of users, this is sufficient protection from the threats that they face. The chance that someone both knows your password and is close enough to steal your yubikey is incredibly unlikely. If y…

[deleted]

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#47

I think the concept is really cool and it’s awesome that Linux makes it relatively easy to play around with authentication methods. I love this kind of stuff. But I’m also a pragmatist. While I run Linux everywhere I reasonably can, my daily driver is macOS and I can’t help but wonder if a fingerprint reader would be a better solution. On my Mac, the fingerprint reader can unlock the system immediately and works acro…

As a daily user of Linux for the best part of a decade I'm curious where Linux falls short for you?

The major one is deep integration of applications with the OS. One example is any keyboard shortcut in any application can be remapped at the OS level. Dictation and services available almost everywhere text can be entered. Any text in almost any dialogue is selectable. Application dialogs like open and print are standardized. The print dialog is incrediably rich with functionality, in every application. This extends to integration with iOS devices and system hardware.

The stock OS is ready out of the box with a full suite of integrated applications. While there are better versions of all of them, most are high quality. Though, I haven’t found a PDF reader better than Preview and Apple Notes is very hard to beat as a general note taking tool.

The base OS has color syncing. I was able to hook up a professional grade printer, have the OS automatically install the drivers, and produce color accurate prints using Preview. The system print dialog allowed me to fully configure the printer. No specialized tools required. There’s even an iOS app that can do the same thing in a more limited fashion.

Never had a driver issue or had to modify a configuration file to get hardware to work properly. (Have done GUI tweaks via defaults.)

When it comes to specialized applications, there are a lot of excellent applications written specifically for macOS. Some come with iOS apps. (1Password is high on my list.)

Due to the industries I work in, Microsoft Office is a hard requirement. Libre Office is not an option.

Time machine has no equal when it comes to backups and restoring to new hardware. I haven’t done a clean install since 2008. In two hours I can completely clone my current machine.

This is just a few of the many reasons I use macOS. Frankly, they are more important to me than openness of platform or deep control of my devices.

That does not mean I don’t appreciate Linux. I love Linux. There is nothing better for servers than Linux. I have older laptops loaded with Linux but they are a hobby for me.

Linux fills a very important place in the world. Frankly, the world needs open operating system and people who enjoy using it. But I have neither the time, expertise, or inclination to do so on my primary machine.

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#49
Hey author, why did you use the words "touchless" and "contactless" when it's not true and not even relevant to the technology being used?

There's something strange going on here, like this article was written by AI or something. It's using words out of context, or just making plainly/obviously false statements.

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#50

Earlier quoted context omitted.

As a daily user of Linux for the best part of a decade I'm curious where Linux falls short for you?

The major one is deep integration of applications with the OS. One example is any keyboard shortcut in any application can be remapped at the OS level. Dictation and services available almost everywhere text can be entered. Any text in almost any dialogue is selectable. Application dialogs like open and print are standardized. The print dialog is incrediably rich with functionality, in every application. This extends…

Don't worry in not one of the zealots that'll try and convince you that Linux has a suitable replacement for something then recommend some this that does t match up (see you MS Office vs. Libre Office for example). Just genuinely interested to know where Linux is lacking for some people (and thus something I might be missing). While I'm definitely an open source advocate I too am a pragmatist and will happily use closed source software and gasp pay for software when the open source alternatives are lacking.

Personally none of you use cases have even crossed my mind, I can count the number of things I've printed in the last decade on 10 years. I can definitely see the benefit of having tight coupling between accessories/phone apps though.

Post reply on HN