Live data from Hacker News

Using a Yubikey as a touchless, magic unlock key for Linux

kliu.io

71–74 of 74 posts

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#71
post #48

So anyone can take my Yubikey and use it to gain access to my computer without so much as a PIN? Is that a good idea?

To be fair, that's also how cars and houses tend to work

Until recently, neither were typically Internet-connected.

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#72

A permanently attached Yubikey is not worse than a password alone, and is still superior to SMS 2FA. It still requires that an attacker know both your password and have physical possession of your machine. For the vast majority of users, this is sufficient protection from the threats that they face. The chance that someone both knows your password and is close enough to steal your yubikey is incredibly unlikely. If y…

i dont get why it's better password and 2FA? leaving yubikey unattended, it will only require attacker to know the password (PIN).

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#73

A permanently attached Yubikey is not worse than a password alone, and is still superior to SMS 2FA. It still requires that an attacker know both your password and have physical possession of your machine. For the vast majority of users, this is sufficient protection from the threats that they face. The chance that someone both knows your password and is close enough to steal your yubikey is incredibly unlikely. If y…

> If you’re the kind of person liable to get personally targeted for nation state level attacks, then you definitely are going to want to unplug your yubikey and keep it on your person.

Maybe yes, maybe no. Do you have a backup YubiKey? If so, then you need to keep it in a separate location (i.e. don't defend against losing your keys by putting both your primary and your backup on the same physical keychain). Are you putting it in a safe? What safe can you buy that is sufficient protection against nation-state level attacks? How often do you check your safe to make sure that your backup hasn't been stolen? What process do you have in place to revoke and replace your backup YubiKey in case you do discover that the backup has been stolen (do you have a list of every website at which you ever enrolled the backup, and how do you safeguard the list)?

IMO unless you are very seriously paranoid, you buy a "nano" in-slot YubiKey if your usage pattern targets a single machine, and a keychain YubiKey (with NFC) if you need portability between, say, your work laptop, your home desktop, and your phone. It's not a question of security but of your usage pattern.

Re: Using a Yubikey as a touchless, magic unlock key for Linux

#74

Earlier quoted context omitted.

I'm trying to move my daily driver from macOS to Linux. (Why? Privacy, more control over how technology interacts with me, and because at a really deep level, I know this is the expression of my authentic self. I don't like to 'blindly accept' things from others without questioning it, and I like to create. I also love to learn. All this is balanced with the desire to just sit back and enjoy a smooth experience like…

Personally I use NextCLoud for things like Notes[1], while it is a web app it is self hosted. Obviously this means you then need to run NextCloud yourself which is an entirely different problem.

Thanks for that, I'll check it out! Not afraid to self-host my entire cloud, makes sense.
Post reply on HN