I've always had it drilled into me that doing crypto yourself is fraught with peril. It seems that doing hardware would be doubly dangerous. I'd want more verification that the implementation is correct and "strong".
Support for U2F security keys
71–80 of 164 posts
Re: Support for U2F security keys
#72Earlier quoted context omitted.
The way $dayjob makes this work is to issue a nano security key for each computer, and then a bluetooth security key for the iPhone (Android phones can use both NFC and Bluetooth security keys, but iPhones can only use Bluetooth security keys). It's cumbersome, but less so than when we were plugging and unplugging our one hardware USB-A OTP token into everything (and using a desktop web browser to generate OTPs for t…
What happens if your house burns down with everything in it? You’d then have to contact support to let you bypass 2FA, but if that’s possible then the 2FA protection is weak, prone to social hacking.
Re: Support for U2F security keys
#73I'm seeing several links to different physical keys in the comments. Is there somewhere/someone that verifies these keys? Like a 3rd party testing/standards body? I've always had it drilled into me that doing crypto yourself is fraught with peril. It seems that doing hardware would be doubly dangerous. I'd want more verification that the implementation is correct and "strong".
What you might want to look at is things like hardware hardening or side channels. (Whether or not you consider this a matter of "correctness" can be argued, but here I would consider correct = implements correct algorithm.)
I think attacks against U2F devices are fairly difficult because you can't really use them as any kind of oracle, just due to the way the user interface works. But I am not a crypto expert, I just know how U2F works.
Re: Support for U2F security keys
#74Got a free YubiKey from Wired. Then I read that mobile is a pain, and that I really need two ... it's sat in my bag now for months, unused. I already use 2FA, and it works good enough - I'm not sold on how this will make my life better, especially on mobile.
Re: Support for U2F security keys
#75Got a free YubiKey from Wired. Then I read that mobile is a pain, and that I really need two ... it's sat in my bag now for months, unused. I already use 2FA, and it works good enough - I'm not sold on how this will make my life better, especially on mobile.
I also got the Wired YubiKey and had the same hesitation. I ended up purchasing a newer model YubiKey with NFC; I use the new one as my primary and the older model as the backup kept at home.
Re: Support for U2F security keys
#76Earlier quoted context omitted.
Which don't? For all the big major ones I've used U2F with, they've supported multiple keys for a while (or since introduction). It's practically a requirement in case you lose a key.. To name a few off the top of my head: Google, GitHub, Gitlab, Facebook, 1Password, etc.
Vanguard (where my company has their 401k plan) is one I have encountered that only supports a single Yubikey.
Re: Support for U2F security keys
#77Re: Support for U2F security keys
#78Re: Support for U2F security keys
#79If this is the sort of thing where I can just tell 1password this device is OK with 2 factor, once per device, I could use this. If this the sort of thing that whenever I wanted to lookup a password, forget it. Even if I had to two it once a week or once a month I wouldn't bother. Maybe if I were paranoid about being a target I would, but I'm not.
> Last year we added two-factor authentication to provide another layer of protection for your 1Password account. When this is enabled, you are prompted to enter your second factor any time you sign in from a new device.
If you read it carefully, you'll have the answer to your question.