Live data from Hacker News

How to Yubikey

debugging.works

71–80 of 186 posts

Re: How to Yubikey

#71

Earlier quoted context omitted.

YubiKeys are more fragile than phones. One time a drop of water got on my plugged-in YubiKey and it stopped working for 2 days

I don't understand this perspective. I dropped my phone one time and could never unlock the screen again. It shattered into a dozen pieces. I've dropped my YubiKey many times with no damage. It has no moving parts. No glass. No screen. A tiny OS. Not much to go wrong.

Absolutely this. My yubikeys have been on keychains for years and all still work. These keys are occasionally dropped, thrown, have gotten wet, fallen into the sand, and the yubikeys are fine.

Re: How to Yubikey

#72
post #69

Earlier quoted context omitted.

You can buy dust covers for USB-C male connectors.

Sure, but that doesn't help against the springs mechanically wearing out, or mechanical damage bending the hollow part of the USB-C connector. Looking at all of my USB-C keys, most of them get visibly bent inwards after a couple of years of carrying them in a pocket on a keychain with other keys. It's hard to imagine a USB-A key breaking in the same way. The only thing that could conceivably break it is the PCB itsel…

Yes, I have both an A and a C in use. If I could keep an A-to-C adapter on my keychain that would be a good option as well.

Type A is more durable, for sure.

Re: How to Yubikey

#73

The 32 TOTP limit was what killed it for me as a replacement for Authy/Google Authenticator/etc. I know Yubikey came out before TOTP really hit its stride, but 32 was really short-sighted.

I thought so as well, but I'm still not nearing that limit and I don't think I will as more places offer FIDO2/WebAuthN.

Re: How to Yubikey

#74
post #9

The thing missing for me is, how to set 2 yubikeys to be functionally the same, to make having a backup key easier (for situations where no data is added to the key)

You have to register each key individually.

This is trickier with TOTP, since you either have to have multiple keys on you or you have to save the TOTP seed / QR code until you have access to the other keys.

Re: How to Yubikey

#75
post #55

Other than Google Titan and Yubikey, are those really the only two players? I find it concerning that there is this whole ecosystem built around security keys, but only two companies making them. That said I currently use yubikeys for all my stuff, it just occurred to me its odd there isn't a bunch of companies making these :/

SoloKeys[0] are one alternative

[0] https://solokeys.com/

Re: How to Yubikey

#76
post #64

Missing from all this: a dedicated machine running Linux to set everything up. I have an old beat up Thinkpad that I use exclusively for critical stuff that would really hurt me if somebody hacked. You can have one for less than the price of Yubikey so there really isn't much excuse.

What's the benefit of that? The entire point of using a security key is that its security model can survive a point in time compromise of the device you are connecting it to, i.e. a compromise only persists as long as a (hopefully short-lived) session. But if a single session compromise is unacceptable to you, by the same token a security key can't protect you against that. The only instance where a "more secure" com…

Whatever security system you have there is always a problem of original sin. This is when attacker happens to be present and prepared to hijack your initialisation process.

If an attacker has unrestricted access to your laptop or phone and you are trying to use this device to set up say your AWS root account, no amount of Yubikeys will help you. They can essentially craft everything you are seeing on the screen and intercept everything you are typing in. What they do with it only depends on their imagination but with the advent of AI powered tools I expect hacking tools are going to get much "smarter" very quickly.

A coworker lost all money he saved for many years for the downpayment on his apartment. He used his laptop to manage his banking and his phone to receive SMS messages. He logged in to his banking from his phone JUST ONCE. That was enough. Apparently, he had some kind of malware on his phone that was waiting in hiding for this exact occasion and the moment he logged in it intercepted the credentials and was able to transfer money out of his account with the codes he got on the same phone. It wasn't even targeted attack. And it was 10 years ago.

And as far as Yubikeys I would suggest they matter less than people think. They are useful concept but only if services providing MFA capability implemented it correctly. And as far as my experience goes, no large service I use at the moment implements this correctly.

The biggest problems are usually defaulting to SMS/email code if you indicate you've lost your Yubikey. Even for services that don't do this, there is usually some way to recover access anyway.

I have lost both my root password and two my yubikeys to my AWS account. Guess what, couple phonecalls later I got my access back. It was stupid for me to loose my credentials (but it was empty account at that time) but it is not inspiring confidence in me that anybody with just the access to my phone number and possibly couple scraps of personal information can recover full access.

My strategy right now is to compartmentalise critical services that I use -- use separate device to access them, never use my other devices for this, use separate email and separate phone numbers. Never reveal to anybody the email and phone number. Never put anything that could create any interest for those services, emails, phone numbers, etc. Yubikeys are nice gimmick (that I use daily) but I honestly don't see them as doing much for my security.

Re: How to Yubikey

#77

Earlier quoted context omitted.

YubiKeys are more fragile than phones. One time a drop of water got on my plugged-in YubiKey and it stopped working for 2 days

I don't understand this perspective. I dropped my phone one time and could never unlock the screen again. It shattered into a dozen pieces. I've dropped my YubiKey many times with no damage. It has no moving parts. No glass. No screen. A tiny OS. Not much to go wrong.

If it was an Android, you can actually plug a mouse into it. I used this to backup a bunch of stuff after I broke my screen and touch no longer worked.

Re: How to Yubikey

#78
post #64

Earlier quoted context omitted.

What's the benefit of that? The entire point of using a security key is that its security model can survive a point in time compromise of the device you are connecting it to, i.e. a compromise only persists as long as a (hopefully short-lived) session. But if a single session compromise is unacceptable to you, by the same token a security key can't protect you against that. The only instance where a "more secure" com…

Whatever security system you have there is always a problem of original sin. This is when attacker happens to be present and prepared to hijack your initialisation process. If an attacker has unrestricted access to your laptop or phone and you are trying to use this device to set up say your AWS root account, no amount of Yubikeys will help you. They can essentially craft everything you are seeing on the screen and i…

> If an attacker has unrestricted access to your laptop or phone and you are trying to use this device to set up say your AWS root account, no amount of Yubikeys will help you.

They will absolutely help against a persistent compromise of my accounts. For example, I can check all registered security keys from a different machine and network.

If only the ones I expect are present, I can click the (hopefully present) button "log out all sessions on all devices" and be reasonably certain that, at least from that point in time, nobody else has account access. And I can make sure that all of the ones present are in fact my keys by trying to authenticate with all of them.

Registering a new key will hopefully also trigger a big scary warning email/SMS/fax to me and/or additional security contacts.

> Even for services that don't do this, there is usually some way to recover access anyway.

As a user, I sure hope there is – it would be genuinely frightening to know that my account is unrecoverable if I lose all security keys linked to it! Hopefully, that process involves a lot of red tape and not just an SMS-OTP or sending a blurry scan of my birth certificate to an e-notary several timezones away.

Re: How to Yubikey

#79
It's pretty annoying having to touch my yubi key every single time. I find KeePassXC + TOTP much more user and disaster resilient. If I lose my yubikey, I'd better have a physical backup copy. If I lose my keypass device, my file is just up on Dropbox. I find the value proposition is outweighed by the risk of disaster for yubikey personally, and keepass doesn't make me touch it every time so it's much more convenient.

Re: How to Yubikey

#80

The attack surface of yubikey vs a laptop you carry around is interesting. Nobody seems to reflect that if you physically steal the laptop, guess what, the usb key that's still in there was also stolen. Anybody using USB locks? If you are focussing on FIDO for password management, I am assuming you are protected against HID emulating devices, like a rubberducky or teensy flashed with some malware installing HID emula…

> The attack surface of yubikey vs a laptop you carry around is interesting. If you use the term "Yubikey" to describe the simplest model of Yubikey and not as a generic term to describe these security keys. Both Yubikey and their competitors are offering more advanced models: models which aren't simply unlocked by a tap on the device. Then the attack surface compared to a laptop you carry around certainly becomes ve…

> now we're talking about Ethan Hawke stealing your laptop, your security key and recreating your fingerprints from a glass he stole at the bar

Why bother with the glass from the bar? Your fingerprints are likely to be all over the laptop.

Post reply on HN