Live data from Hacker News

Passwordless Logins with Yubikey

adl1995.github.io

41–50 of 66 posts

Re: Passwordless Logins with Yubikey

#41
If you have nothing better to do:

1. Get a smart ring like OMNI

2. Shove a USB hub and a contactless reader into your mouse, so if on the next poll your hand with a ring isn't on it - lock it all

Seriously though, if someone would start selling mice with contactless readers built-in, I'd buy a few.

Re: Passwordless Logins with Yubikey

#42
post #19

True security is using both "something you know" and "something you have". Something you have can be stolen, and something you know can be tricked out of you. But stealing both is difficult and far more obvious. To login to my work VPN, the password is " ". Our SSO system requires both once per day as well. It's a great system and I highly recommend it.

Ideally something you „are“ as well. Though in practice this might be overkill for most. I believe there‘s a new biometric yubikey in the works. A fingerprint version of the 5C NFC would be cool.

I get the sense that biometrics are not very future proof. People leave fingerprints and DNA on everything they touch and faces and eyes are seen by cameras all the time. Biometrics work now, but in the near future I suspect the technology to take images of peoples faces/fingerprints and reproduce their likeness to fool a biometric sensor will be a commodity. Once that happens biometrics will be near useless because you essentially have no way to respond to leaked biometric data, it can't be changed.

Re: Passwordless Logins with Yubikey

#43
post #19

True security is using both "something you know" and "something you have". Something you have can be stolen, and something you know can be tricked out of you. But stealing both is difficult and far more obvious. To login to my work VPN, the password is " ". Our SSO system requires both once per day as well. It's a great system and I highly recommend it.

We use the AnyConnect VPN client which allows for a password & 2nd password field for yubikey, same concept. Agree that it works nicely

Re: Passwordless Logins with Yubikey

#44

Earlier quoted context omitted.

How is that? Everybody living in my house can get my Yubikey yet doesn't know my password. If I get robbed, my bank account is still (relatively) safe.

Playing advocate for the idea: There are a lot more people far away from you than there are close to you. If breaking your security requires physical proximity (such as to steal a yubikey), then you are much safer just based on this. It's also easier for people to blindly steal credentials for millions of people online than it is for them to steal millions of physical security keys. Alternatively, passwords are commo…

For the last bit: If it's suitably seamless, it's actually not that bad. I've been carrying one on my keyring, and it's just another key, only this one "unlocks" websites.

Re: Passwordless Logins with Yubikey

#45
post #11

Alternate title: guide to changing your single factor authentication from "something you know" to "something you have."

I think you mean from "something you can forget" to "something you can lose"

I don't remember like 98% or 99% of my passwords. I have something like 270 on my private accounts and probably 300 passwords on my work accounts. Well password manager is useful and I can always use pw reset option built in systems.

I kindly propose everyone to forget all their passwords.

Then they mostly don't need second factor if they generate random password each time and don't care about remembering them at all.

Re: Passwordless Logins with Yubikey

#46

Earlier quoted context omitted.

"Something you have" is generally an improvement over "something you know" for most people's account security. You have to remember where we are starting from - most people are still using the same password across all their accounts.

How is that? Everybody living in my house can get my Yubikey yet doesn't know my password. If I get robbed, my bank account is still (relatively) safe.

Most people in your home are not trying to hack you.

A lot of people outside your home are trying to hack you.

Shifting your exposure from "everyone in the world with an internet connection" to "people who are in/near your home" greatly reduces your risk, objectively.

Re: Passwordless Logins with Yubikey

#47
post #40
post #19

True security is using both "something you know" and "something you have". Something you have can be stolen, and something you know can be tricked out of you. But stealing both is difficult and far more obvious. To login to my work VPN, the password is " ". Our SSO system requires both once per day as well. It's a great system and I highly recommend it.

Amazon?

Shhh!

Re: Passwordless Logins with Yubikey

#48

Earlier quoted context omitted.

Ideally something you „are“ as well. Though in practice this might be overkill for most. I believe there‘s a new biometric yubikey in the works. A fingerprint version of the 5C NFC would be cool.

I get the sense that biometrics are not very future proof. People leave fingerprints and DNA on everything they touch and faces and eyes are seen by cameras all the time. Biometrics work now, but in the near future I suspect the technology to take images of peoples faces/fingerprints and reproduce their likeness to fool a biometric sensor will be a commodity. Once that happens biometrics will be near useless because…

Aah, but will the cameras get enough shots of my tongue? Linguametrics, you heard it here first, folks.

Re: Passwordless Logins with Yubikey

#49

Alternate title: guide to changing your single factor authentication from "something you know" to "something you have."

Current Yubikeys support multi-factor, both knowledge and possession. It is just up to websites to request this.

They have a key coming (some day) which will also support a biometric factor.

Re: Passwordless Logins with Yubikey

#50
post #19

True security is using both "something you know" and "something you have". Something you have can be stolen, and something you know can be tricked out of you. But stealing both is difficult and far more obvious. To login to my work VPN, the password is " ". Our SSO system requires both once per day as well. It's a great system and I highly recommend it.

This is a bit muddied when talking about securing access to something you also have.

That is, you aren't securing your vpn with two factors. You are securing access to your vpn. It is different.

Similarly, for your computer, it is already something you have. Such that the password to login to the machine can already be seen as a second factor. My home password, as an example, is worthless to you without me home computer.

I'm not sure on the argument regarding moving to a physical key to get in the machine. By and large, it seems to be a more transferable method of accessing something. Not more secure, per se. But not less, either. (Right?)

Post reply on HN