Live data from Hacker News

GitHub supports Universal 2nd Factor authentication

github.com

71–80 of 85 posts

Re: GitHub supports Universal 2nd Factor authentication

#71
post #2

This seems less convenient to me than 2FA using Google authenticator. I always have my phone with me. I don't want to bother bringing a USB key between home and work. Is a separate USB key meaningfully more secure?

I've used a YubiKey for 2FA for a year or so now. It just sits in my USB port and it feels too convenient - steal my laptop and you get my key. At least my phone has a PIN.

U2F is protection against someone phishing/stealing your credentials online. Your password is your protection against someone stealing your laptop. The likelihood that a person who steals your laptop also managed to phish/steal your credentials is minute.

Re: GitHub supports Universal 2nd Factor authentication

#72
post #64
post #5

Earlier quoted context omitted.

This is actually more convenient sometimes. I already have one of these FOBs permanently attached to my computer. It's a tiny pieces that fit into usb and only protrudes a couple of milimiters. Since I have this always connected all I have to do is touch it and I'm in. Takes me less than once second while taking my phone, opening the app and typing the code by hand takes 10-20 seconds. The downside is that it takes a…

Dumb question... what does the yubikey then do that a normal computer can't do? If you keep it plugged in, what security benefit does it have over storing (strong) passwords?

Think of it the same as the EMV chip on a credit card.

Re: GitHub supports Universal 2nd Factor authentication

#73
post #19

I never understood the point of 2-factor authentication, and moreover, certain agencies (e.g. banks) that force using it. Can't we just pick good enough passwords? Personally I hate being {attached to|associated with|being required to carry} a particular piece of hardware; I much prefer that information freely flows with me as I move between the various devices I interact with over the course of a day. There are many…

  > I never understood the point of 
  2-factor authentication
Ouch. People choosing bad passwords has been mentioned already but the real reason is because it protects against a broad range of MITM attacks as well as some sorts of phishing attacks.

Re: GitHub supports Universal 2nd Factor authentication

#74
Just a warning with the yubikeys. I had to use a solution that had these for a few months. The USB port of my laptop (2011 MBP) was pretty much worn out due the physical insertion and removal - other stuff would just fall out. Eventually this port blew entirely stopped working.

This is not specific to the MBP as a colleague's ThinkPad had the same problem.

Re: GitHub supports Universal 2nd Factor authentication

#75

Sod the Yubikey. Get a Pebble Time watch and install the QuickAuth app. One press of a button on my watch and I get a list of two factor auth codes for my various services, now including Github. Doesn't require plugging anything into my laptop. Doesn't require my phone to be near me or on. Doesn't require Internet access.

TOTP is vulnerable to phishing and MITM attacks. U2F (assuming that you are not MITMed when registering the device) is not.

Re: GitHub supports Universal 2nd Factor authentication

#76
post #24
post #14

If you want to try for one of the 5,000 $5 Yubikey with everyone else currently killing the server... 1) sign in with github at: https://www.yubico.com/github-special-offer/ 2) buy now: https://www.yubico.com/github-special-offer/github-yubikey-s... 3) checkout: https://www.yubico.com/checkout/ Once you complete one step successfully you should be able to skip to the next. Good luck vs. the 504's!

The only international shipping option I can see is DHL Express for $65.00 :(

There are competitors producing U2F keys, I see one for £4.99 / €5.99 on Amazon.(co.uk|de|fr).

Re: GitHub supports Universal 2nd Factor authentication

#77
post #18
post #8

I can't think of a single compelling reason to use this over Google Authenticator.

It's faster. No typing. No worry about malware stealing your OTP secret. It's easy to revoke a single device if you lose it without having to change your Authenticator secrets everywhere. And it looks cool.

Also, phishing and Man-in-the-Middle protection.

Re: GitHub supports Universal 2nd Factor authentication

#78

Uh. U2F feels incredibly limited compared to PKCS#11 I really wonder why it was chosen (and somewhat disappointed by the choice.) With a smartcard that can hold an key pair, one can both authenticate (sign) and encrypt messages, using a same single key (or multiple keys if wish for multiple identities). With U2F all one can is authenticate, using a distinct securely-stored PSK for each remote party.

The infrastructure around smartcards is designed for one enterprise to pay another enterprise millions of dollars to roll out Active Directory-based authentication for a Windows domain with hundreds of thousands of users, for a multinational corporation to roll out a payment card, etc. A single hobbyist maintains an open-source tool that allows applets to be loaded on to GlobalPlatform-compliant cards. It's pretty fr…

Makes sense. Enterprise shit is, indeed, terrible. However, I didn't mean there is any reason to support every JavaCard out there and existing (enterprise) software - and I suppose this is where it all really starts to smell. On the other hand, they have designed a whole new standard, protocol and devices.

I've edited this for quite long time and finally figured out what I really had in my mind. I'm not disappointed it's a new standard or anything like this. I'm disappointed by the fact that this stuff isn't extensible and nothing new can be build upon this.

Not in a sense that no new software can be added to a token, but when you use U2F you just have a means to prove you know some PSK. And that's it. Would the token hold a keypair and use digital signatures instead, it could bring much more possibilities in the long run. Like sending encrypted emails to the token owners, or building a global identity system where identities are something user possesses, not leases from the "identity providers".

Re: GitHub supports Universal 2nd Factor authentication

#79
post #38
post #37

Earlier quoted context omitted.

What if the thing you're trying to access from doesn't have a USB port? Like, an intelligent table surface, a digital wall, a smart goggle device, or even an tablet that only has a micro-USB port? Information flow protocols and hardware should be abstracted and separated in the same way that we generally separate church and state in most modern nations. Otherwise, the innovation of either is going to be pulled behind…

Depends on what you're trying to auth with. For example, I was just reading about activating 2FA on my Google account and the backup options were: * SMS Verification code * Manually generated list of backup verification codes

A lot of services seem to love using SMS-based 2FA. Thing is, I've already made a personal decision to ditch SMS as antiquated technology (along with the telegram), in favor of e-mail, WeChat, WhatsApp, Facebook and other communication alternatives.

Since some apps apparently still want to cling to old technology, I have one SMS-enabled phone number -- a Google Voice number which forwards to my e-mail address. I don't need to carry my phone around to get my SMS messages. But then again, it's not really 2FA anyway, it's just an annoyance; effectively 2 passwords (one to login to the app, one to login to my e-mail to check my SMS messages).

Re: GitHub supports Universal 2nd Factor authentication

#80
post #46
post #29

Earlier quoted context omitted.

In that case, can we do 2FA with something biometric? Or even 2 passwords? A physical component has a lot of issues: * It can be stolen or robbed at gunpoint. Torture, drugging, and hypnosis aside, your mind is much more secure. * It can run out of batteries. * It's one more thing you can lose. It's already annoying enough to have to remember to carry 7 or 8 things every day, including a phone, bike light, smart watc…

The Yubikey does not run on batteries. It requires no cellular service. It can be damaged by the elements but not easily. Most electronics would break before it does. Of course you can lose it, but you can lose anything. Attach it to something you care about, such as your regular keychain. If you want to give access to someone, register a second key and lend that key to them. Then revoke when they don't need it.

What if I don't want to carry keys around? My house door can be opened with a password. I only need to carry myself.
Post reply on HN