Live data from Hacker News

Support for U2F security keys

blog.1password.com

61–70 of 164 posts

Re: Support for U2F security keys

#62
post #25

I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?

A bluetooth capable U2F device like the Titan.

Friendly reminder that "T1" Bluetooth Titan keys were recalled last month; they don't work with iOS 12.3+.

Details are available at https://security.googleblog.com/2019/05/titan-keys-update.ht...

Re: Support for U2F security keys

#63
post #59

Earlier quoted context omitted.

few providers support enrolling multiple yubikeys into your account.

Which don't? For all the big major ones I've used U2F with, they've supported multiple keys for a while (or since introduction). It's practically a requirement in case you lose a key.. To name a few off the top of my head: Google, GitHub, Gitlab, Facebook, 1Password, etc.

Vanguard (where my company has their 401k plan) is one I have encountered that only supports a single Yubikey.

Re: Support for U2F security keys

#66
post #37
post #16

Earlier quoted context omitted.

The primary purpose of U2F/WebAuthn is to break phishing attacks. Code-based TOTP 2FA, the kind you're probably using now, is already adequate to the task of making sure you're not credential-stuffed.

Autofill of a password manager is a working countermeasure against phishing too: If autofill does not work there is something wrong and you should look closer...

Except autofill fails all the time for other reasons. The site has rebranded to a new domain name. They moved the login page or redesigned it. Or it was always badly designed and broke autofill. Or the same credentials are used on multiple domains (think Google, Microsoft).

Re: Support for U2F security keys

#67

This looks awesome and I wish I could use it. Could you guys also consider bringing back the completely-offline mode that doesn't make my password manager depend on a 3rd party service? I'm prohibited by company policy from using my favorite password manager because of this.

Try https://www.enpass.io (I sync db through Dropbox but you can use almost whatever you want...)

Re: Support for U2F security keys

#68
post #25

I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?

so it appears, no, all reasonable solutions are quite cumbersome for the time being, for an individual who wants to use many accounts anyway. a company might be able to cook up a system that works well for its employees though.

Re: Support for U2F security keys

#69
post #56
post #25

I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?

The way $dayjob makes this work is to issue a nano security key for each computer, and then a bluetooth security key for the iPhone (Android phones can use both NFC and Bluetooth security keys, but iPhones can only use Bluetooth security keys). It's cumbersome, but less so than when we were plugging and unplugging our one hardware USB-A OTP token into everything (and using a desktop web browser to generate OTPs for t…

What happens if your house burns down with everything in it?

You’d then have to contact support to let you bypass 2FA, but if that’s possible then the 2FA protection is weak, prone to social hacking.

Re: Support for U2F security keys

#70
post #59

Earlier quoted context omitted.

few providers support enrolling multiple yubikeys into your account.

Which don't? For all the big major ones I've used U2F with, they've supported multiple keys for a while (or since introduction). It's practically a requirement in case you lose a key.. To name a few off the top of my head: Google, GitHub, Gitlab, Facebook, 1Password, etc.

Before this, both LastPass and 1Password said they supported U2F via Duo, but Duo only supported one key, so I could never use it.
Post reply on HN