Live data from Hacker News

How to Yubikey

debugging.works

81–90 of 186 posts

Re: How to Yubikey

#81
post #77

Earlier quoted context omitted.

I don't understand this perspective. I dropped my phone one time and could never unlock the screen again. It shattered into a dozen pieces. I've dropped my YubiKey many times with no damage. It has no moving parts. No glass. No screen. A tiny OS. Not much to go wrong.

If it was an Android, you can actually plug a mouse into it. I used this to backup a bunch of stuff after I broke my screen and touch no longer worked.

You couldn't see it either, but I suppose I could have fumbled around a bit blind. Good call.

My wife and I have had really good luck buying matching phones.

That time one had stopped charging and was replaced with a super-budget phone, so I just swapped screens, backed up/exported what I needed, and moved on.

Re: How to Yubikey

#82
I actually just bought two Yubikeys. I figured the iCloud announcement was reason enough to pull the trigger on them.

I was actually surprised at how little changes I needed to do, it “just worked” with the most sensitive accounts I had (1Password, Gmail, iCloud). Very cool devices.

Re: How to Yubikey

#83
post #78

Earlier quoted context omitted.

Whatever security system you have there is always a problem of original sin. This is when attacker happens to be present and prepared to hijack your initialisation process. If an attacker has unrestricted access to your laptop or phone and you are trying to use this device to set up say your AWS root account, no amount of Yubikeys will help you. They can essentially craft everything you are seeing on the screen and i…

> If an attacker has unrestricted access to your laptop or phone and you are trying to use this device to set up say your AWS root account, no amount of Yubikeys will help you. They will absolutely help against a persistent compromise of my accounts. For example, I can check all registered security keys from a different machine and network. If only the ones I expect are present, I can click the (hopefully present) bu…

> Registering a new key will hopefully also trigger a big scary warning email/SMS/fax to me and/or additional security contacts

If your devices are compromised you are not guaranteed to receive any emails or SMS. There are malwares known to remove emails and messages either directly or by running as man in the middle or by intercepting and modifying the UI.

> As a user, I sure hope there is – it would be genuinely frightening to know that my account is unrecoverable if I lose all security keys linked to it!

As a professional I am reading it the following way:

"The access to the account can be regained without the super duper secure Yubikey fleet you have."

Therefore it is as secure as that super expensive door lock when there is an open window right next to it.

> Hopefully, that process involves a lot of red tape and not just an SMS-OTP or sending a blurry scan of my birth certificate to an e-notary several timezones away

But that just does not happen. This would be super expensive and companies would rather limit their involvement with individual people to save on support cost. All I got from AWS was two phonecalls from a tired guy with obvious Indian accent.

Re: How to Yubikey

#84
post #19

Earlier quoted context omitted.

Most people have only their phones, which can also break. But some people only start thinking about that stuff when they look at alternatives like the Yubikey. > they can just break when plugged into a laptop that takes a dive So can the laptop at a conference. Or anything else really. I just remove my Yubikey after use and carry it in my wallet when not in use. Sure, I can lose my wallet, but I have multiple back-up…

In normal life losing access to your phone won't lock you out of everything. You still have all your other devices you can use AND you can always just walk into store and buy yourself a replacement and download your phone back from a backup. Same with laptops. If you go to a conference and your laptop breaks. You can just go to nearest store and buy a new one. It will take couple hours, but you'll be up and running a…

I can still get into "life stuff" without my Yubikey. There are increases in risk to doing so (TOTP requests have decreased resistance to phishing attacks versus webauthn, for example), which is why I don't do that generally, but the fallbacks are not a serious problem.

I would have to lose/break my phone and my laptop (both secured via Apple's stuff, not my Yubikey) and my Yubikey to be materially locked out of things. And, at that point, my password vault is inaccessible to me and I have much bigger problems.

The only thing I cannot do without a Yubikey is SSH into systems, and that is, for me, a worthwhile thing to break-glass on.

Re: How to Yubikey

#85
There was a very good security key dissection article way back on the net, just couldn't find it in my archives. They removed the ceramic coating, checked signals etc. and came to a quite sobering conclusion regarding security keys. If anyone has something similar, please provide a link.

Re: How to Yubikey

#86

I like the idea of securitykeys, but having to drop 100€ for a key (since in my opinion you are playing with fire if you don't buy a backup) feels like excessive and then having to worry that I remember to take my securitykey with me everywhere... Yeah, yeah, security vs. convenience is always the issue, but so far I've just selected convenience.

If you setup a domain to use Cloudflare, and then sign up for their zero trust system, you can get a code to get up to 4 yuibkey's for $10 each.

Re: How to Yubikey

#87
With the way things are going (U2F/WebAuthn), Yubikeys are being commoditized, and that's a good thing. I have 5-6 Yubikeys, but nowadays the one I use most is the Solo 2 I embedded in my laptop[0].

Pretty much the only thing I use a Yubikey for nowadays is U2F, and I might as well use any cheaper key for that, since they're all equivalent (Solo 2 even has much more space for resident keys).

I don't think there's much reason to get a Yubikey nowadays, especially if you don't need it for some specific use case (e.g. GPG). Just buy any cheap FIDO2-compatible key and you're good.

[0]: https://www.stavros.io/posts/making-a-security-key-for-the-f...

Re: How to Yubikey

#88
post #50

> I don’t see any use case or security benefits by using the static password feature. Even if you enter a password manually and concatenate it with the password of the Yubikey, a keylogger still gets both parts (assumption: You don’t reuse passwords). If keylogger is what you're defending from, yes, it doesn't help. And in this scenario you've probably already lost. On the other hand, it makes a large portion of the…

Also: something you don't know is also something you cannot tell the person threatening you with the 5$ wrench¹

¹: https://xkcd.com/538/

Re: How to Yubikey

#89

There was a very good security key dissection article way back on the net, just couldn't find it in my archives. They removed the ceramic coating, checked signals etc. and came to a quite sobering conclusion regarding security keys. If anyone has something similar, please provide a link.

Unless the conclusion was "someone can steal the private key from the key just being plugged in to USB", it can't have been very sobering. Literally all I want from a USB key is to make it so physical theft is required before someone can access my stuff.

Re: How to Yubikey

#90

I like the idea of securitykeys, but having to drop 100€ for a key (since in my opinion you are playing with fire if you don't buy a backup) feels like excessive and then having to worry that I remember to take my securitykey with me everywhere... Yeah, yeah, security vs. convenience is always the issue, but so far I've just selected convenience.

Buy any FIDO2-compatible key for 15-20 EUR, they all do the same thing (or use TouchID if you're using a Mac, but you'll want backup for that).
Post reply on HN