Live data from Hacker News

YubiKey 4C

yubico.com

51–60 of 266 posts

Re: YubiKey 4C

#51

Earlier quoted context omitted.

Apple decided that users cannot use the NFC chip in it except for Apple Pay (for the foreseeable future). You don't really 'own' an Iphone in that sense.

users cannot use the NFC chip in it except for Apple Pay That... boggles my mind :-O Thanks for the info. My wife is unfortunately locked into iPhone due to work standard, but something to keep in mind long-term.

That's it - iPhone is the new Blackberry.

Re: YubiKey 4C

#52

I have a Yubikey, but almost never use it. I still don't get it fully, don't have a use-case where it totally works for me. Having one key is maybe part of the problem. If I lose it, what then?

I was pretty paranoid about moving to 2FA for my personal account due to fears about getting locked out, but finally decided to take the plunge when I got a yubi for my work & realized I could also add my personal account to it. The nice thing about the Yubi is that decreases the chances you'll be locked out, because (if you're using it for a Google account, then) you still have a phone app, like Google Authenticator, that you can use to authenticate. And you've still got backup codes. And I also have two keys.

Re: YubiKey 4C

#53

Kind of useless to have a C-only device this early. An A/C-hybrid would be much more useful, like Kingston's MicroDuo[1] series. [1]: http://www.kingston.com/us/usb/personal_business/DTDUO3C

They sell a Yubikey 4 with USB-C adaptor which looks like what you want: https://www.yubico.com/product/yubikey-4-nano-usbc-bundle/ Looks around the same size as Yubikey 4C.

Re: YubiKey 4C

#54
post #40
post #22

Until there's a YubiKey 4C nano, I'll wait. Having something of that size sticking out of my computer is not really practical. Not having it inserted defeats the whole point.

I'm kind of wondering what the benefit is over having something like Yubikey at all instead of something that's just software when you just leave it in all the time.

Trust: a hardware token has a very limited interface where it can be attacked compared with a general purpose computer or phone.

Take the devices you use: how many exploits have there been in the last year where an attacker who could get you to click on a link, view an image, etc. could run code on the device? Maybe you have something like the iOS sandboxing between application which would stop a compromised browser from compromising your authenticator app but there are many cases where attackers have been able to bypass that.

Using a hardware token prevents almost all of those attacks and means that if you are compromised you'll have an easier time regaining control. They also have some nice benefits such as not running out of battery when you need them in an emergency.

Re: YubiKey 4C

#55

I have a Yubikey, but almost never use it. I still don't get it fully, don't have a use-case where it totally works for me. Having one key is maybe part of the problem. If I lose it, what then?

[deleted]

Re: YubiKey 4C

#56

I have a Yubikey, but almost never use it. I still don't get it fully, don't have a use-case where it totally works for me. Having one key is maybe part of the problem. If I lose it, what then?

I'm in the same boat and actually submitted an "Ask HN" awhile back to see what others were doing (https://news.ycombinator.com/item?id=13567209). I have the plain ol' yubikey and also the NFC yubikey but I haven't found a good, real world use case for them. It might be that I'm just not the target market or that I haven't put enough time/effort into it. For me the big selling point was the FIDO stuff but so few providers seem to use that...

Re: YubiKey 4C

#57
post #25

What are the current alternatives to Yubikey? Preferably looking for something open-source and in no way associated with Google.

The U2F zero was on amazon for a while. But not anymore.

Unfortunately the guy who is doing it no longer has time for it.

Re: YubiKey 4C

#58
Note that this isn't just a U2F key; if you're looking for a token principally to log into web services with, this isn't what you want, and the token that does that costs less than half as much (it's the U2F-only token).

You want a Y4 if:

* You SSH into sensitive machines.

* You log into a VPN that you control and can configure to use the Y4.

* You're actually relying on PGP.

Post reply on HN