Live data from Hacker News

Ask HN: Alternatives to Yubikey?

news.ycombinator.com

61–70 of 91 posts

Re: Ask HN: Alternatives to Yubikey?

#61
post #57
post #44

Earlier quoted context omitted.

I use my yubikey and I love it. I have it set up to do GPG, SSH, TOTP, and U2F and it works great. It is worlds better then any other Smart Card or second factor out there, and U2F is literally just plug it in and tap it.

Is there any sort of backup in case it gets destroyed or lost? Can you clone it?

The entire security model depends on the devices being uncloneable.

Re: Ask HN: Alternatives to Yubikey?

#62
post #61
post #57

Earlier quoted context omitted.

Is there any sort of backup in case it gets destroyed or lost? Can you clone it?

The entire security model depends on the devices being uncloneable.

But my security model does not allow putting myself in a position where I am stranded without my second factor (or doing huge amounts of work re-registering everything).

Re: Ask HN: Alternatives to Yubikey?

#63
post #62
post #61

Earlier quoted context omitted.

The entire security model depends on the devices being uncloneable.

But my security model does not allow putting myself in a position where I am stranded without my second factor (or doing huge amounts of work re-registering everything).

That's why you set up backup factors.

It is for the same reason that services like Google Mail won't let you set up a U2F token without a backup factor.

Re: Ask HN: Alternatives to Yubikey?

#65

I recommend the OnlyKey: https://www.amazon.com/OnlyKey-Color-Password-Manager-Obsole... The device uses strong encryption (where legal), and goes beyond U2F to include password management, certificate storage, OTP/Google Auth, and plausible deniability. The hardware is teensy-based, and the firmware is open source. The devs have released fairly regular updates, and even encourage hacking on it to meet custom needs.

I love the feature they keep passwords in fact on the device itself, not as a key to enable password manager. I was looking for something like that. If only they offered strong encryption for Europe!

Re: Ask HN: Alternatives to Yubikey?

#67
post #45

SecurID has been the gold standard for more than a decade. Not to dismiss YubiKey but companies that can afford 2 factor and take security seriously already have SecurID for a long time.

SecurID is just an expensive TOTP implementation (although a very established one, as you noted) That "gold standard" required reissuing 40 millions of devices in 2011 due to a single server breach. Lockheed-Martin was apparently really, really happy about it, too. If that's your desired level of security, just use any TOTP authenticator app on your smartphone.

SecurID also does private key, certificate authentication and much more. The TOTP is just one of many options.

A lot of mails going to the post office. That's one of the good thing about this hardware tokens, you can decommission and replace them easily.

What's expensive it to redo all your applications and systems to have 2 factor authentication.

Re: Ask HN: Alternatives to Yubikey?

#68

The DIY open source alternative: https://u2fzero.com/

Is...that...safe? I'm all for the a DIY solution, but considering how much of a pickle I'd be in if all of my 2FA tokens were inaccessible, wouldn't the average person want some kind of case or shielding around the exposed board? Give me an enclosure like Samsung's metal flash drives[0], and then I'd be sold. [0] https://www.amazon.com/Samsung-METAL-Flash-MUF-32BA-AM/dp/B0...

Those Samsung flash drives are nice, I have several. ~22MB/s write, and ~130MB/s read.

Re: Ask HN: Alternatives to Yubikey?

#69
post #49
post #48

Out of curiosity... is Google Authenticator dead? The iOS app hasn't been updated in quite a while (Feb 22, 2016).

Does it need an update?

I'd love to be able to select the background color of entries and edit the text at the top of the entry, rather than just the bottom.

Re: Ask HN: Alternatives to Yubikey?

#70
I too had poor experience with support and also weak documentation, but I pushed through it and I'm very happy with the product now that it's integrated with my app. They seem to practically 'own' the space and I have some confidence in the longevity of the product.
Post reply on HN