Live data from Hacker News

Support for U2F security keys

blog.1password.com

51–60 of 164 posts

Re: Support for U2F security keys

#51
post #25

I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?

krypton (https://krypt.co/). If you're ok with one dongle, you can get the A or C flavor of a yubikey neo and keep a converter permanently in the other devices.

Re: Support for U2F security keys

#52

Got a free YubiKey from Wired. Then I read that mobile is a pain, and that I really need two ... it's sat in my bag now for months, unused. I already use 2FA, and it works good enough - I'm not sold on how this will make my life better, especially on mobile.

The free YubiKey from Wired is a base model. It doesn't have NFC/Bluetooth etc. But if you get the latest model from this article's promoted model (YubiKey 5) it will have all the bells and whistles for mobile/USB-C/contactless and even supports PIV SmartCard protocol, where you can upload a key pair you generated on your own outside of YubiKey.[1]

[1]: https://www.yubico.com/wp-content/uploads/2018/09/yk5-diagra...

Re: Support for U2F security keys

#53
I've had an OnlyKey for a couple of years now. It offer 12 slots per profile and 2 profiles, and the slots supporting TOTP, U2F, Yubikey, plaintext and a whole lot of other tools. With the configuration app and firmware open source, I'm really surprised I've never seen anyone else with one.

Re: Support for U2F security keys

#54
post #48
post #25

I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?

Usually you just use multiple keys - one USB-C in the MacBook, one tiny USB-A in the laptop and the built-in Titan key in the Pixel phone. You don't remove them.

few providers support enrolling multiple yubikeys into your account.

Re: Support for U2F security keys

#55

Earlier quoted context omitted.

Interesting. If this is the case, I think you have a communications problem. I was under the impression that after 6.0, the only way to get a license was to have your older one grandfathered. I can't find any information about this on your website. All of the options on your product info pages other than "enterprise (email us for a quote)" show monthly subscriptions only. Where can I see product info about the licens…

This was so difficult to figure out, and responses from AgileBits support so disingenuous, that I wrote up how to do this on iOS: https://www.davidschlachter.com/misc/1password-ios-standalon...

"Disingenuous" is really how it feels to me too, unfortunately. Doesn't give me a warm fuzzy feeling about them being committed to supporting it. But I have to admit, the clear answer from Kyle in this very thread gives me hope. I will definitely be upgrading my 6.0 license to 8.0. AgileBits: please keep the licensed version forever, and try not to make it seem like such a step-child. :D

Re: Support for U2F security keys

#56
post #25

I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?

The way $dayjob makes this work is to issue a nano security key for each computer, and then a bluetooth security key for the iPhone (Android phones can use both NFC and Bluetooth security keys, but iPhones can only use Bluetooth security keys).

It's cumbersome, but less so than when we were plugging and unplugging our one hardware USB-A OTP token into everything (and using a desktop web browser to generate OTPs for the phones).

If you do end up getting a security key, I recommend getting at least two. If one fails, you'll want the other one as a backup so that you can get back into your accounts.

Re: Support for U2F security keys

#57
post #37
post #16

Earlier quoted context omitted.

The primary purpose of U2F/WebAuthn is to break phishing attacks. Code-based TOTP 2FA, the kind you're probably using now, is already adequate to the task of making sure you're not credential-stuffed.

Autofill of a password manager is a working countermeasure against phishing too: If autofill does not work there is something wrong and you should look closer...

"looking closer" is not an effective countermeasure against phishing, that's the fundamental problem U2F keys are supposed to solve.

Re: Support for U2F security keys

#58
post #48

Earlier quoted context omitted.

Usually you just use multiple keys - one USB-C in the MacBook, one tiny USB-A in the laptop and the built-in Titan key in the Pixel phone. You don't remove them.

few providers support enrolling multiple yubikeys into your account.

This is true, and it is dangerous (once the key fails, folks get locked out). I don't use security keys with such providers.

It would be nice if someone made a library that made incorporating Webauthn login into an app as simple as using django or Ruby on Rails or React to create a login form, so folks don't end up rolling their own and assuming that a user will have at most one yubikey.

Failing that, you could do what Zeit does and rely on email providers' support for Security Keys (login by email link only).

Re: Support for U2F security keys

#59
post #48

Earlier quoted context omitted.

Usually you just use multiple keys - one USB-C in the MacBook, one tiny USB-A in the laptop and the built-in Titan key in the Pixel phone. You don't remove them.

few providers support enrolling multiple yubikeys into your account.

Which don't? For all the big major ones I've used U2F with, they've supported multiple keys for a while (or since introduction). It's practically a requirement in case you lose a key..

To name a few off the top of my head: Google, GitHub, Gitlab, Facebook, 1Password, etc.

Re: Support for U2F security keys

#60

I have never used 1password.com. Adding 2FA to it is great but I think the best security is likely still just to sync and use local apps for this data, to avoid being exposed to any JavaScript vulnerabilities or if 1password.com were ever hacked.

1Password has Wifi Sync option too.

Yep! 1password is great. I do use their cloud sync service with all the apps, I just don’t ever use the website or the browser extensions to limit my exposure.
Post reply on HN