Live data from Hacker News

That's not how 2FA works

shkspr.mobi

91–100 of 269 posts

Re: That's not how 2FA works

#91
post #30

Earlier quoted context omitted.

I have helped literally hundreds of people setup Yubikeys across several companies. Your take is just not my experience at all. Tapping a blinking light it is much easier than fussing with a 2FA app and works when someone's phone is dead. Yubikeys in particular are near indestructible. They even work after you soak them in acetone overnight and melt the plastic off. I tried. When it says "plug in your device" you plu…

If my Yubikey gets stolen, how do I log in into my accounts? Serious question; never understood how that works.

I have a backup U2F device. You can register multiple with any account.

If I somehow manage to lose both, I assume I’ll have to talk to a customer support rep or something.

Re: That's not how 2FA works

#92

Earlier quoted context omitted.

For the reasons listed in the article and more, Yubikeys and similar devices aren’t likely to ever be popular. To give future security devices along the same vain a better chance at gaining popularity and being widely adopted (which will hopefully bringing us a more stable, less stressful society), the designs of these new devices must solve or workaround the issues the author describes. It’s really annoying when ind…

I think Yubikey (and similar physical solutions) will eventually gain popularity. Carrying a key is pretty much a standard practice across the globe and benefit is more than negligible because it forces physical attack versus remote/virtual.

I've long thought that U2F should be incorporated into phones, since everyone has one of those. Even not well off people in third world countries. In order for U2F to proliferate, everyone should have access to it. A $10 FIDO key probably won't be given a consideration if they think a free password is good enough.

Re: That's not how 2FA works

#94
post #84
post #19

The Yubikey/WebAuthn comments are really ignorant and discouraging people from the best defense against this sort of attack that exists. First of all you can get WebAuthn devices for as little as $10 now. Second, there is no app to configure. You plug it in when it says register and tap it. Done. Third, if the WebAuthn device gets stolen the attacker presumably lacks a password. You can't use the device by itself. Al…

Plus, iPhones already support webauthn via Face ID, and I assume MacBooks will support it via Touch ID at some point.

It is disappointing that touch id doesn't support this yet, it would be great. I put my ssh keys on touch id but my webauthn and gpg are on the yubikey and I have to remember which to touch. And the yubikey with finger print reader isnt out yet and I already have pretty much the right hardware in the mac...

Re: That's not how 2FA works

#95
post #89

Earlier quoted context omitted.

Disappointed but not surprised when reading this. To be really honest, I can't remember the last time I read something that criticized so called "techbros" and actually said something reasonable. As for the U2F devices, the idea of just leaving them in, the small yubikeys and all that, seem to just be a bad idea from the get-go.

What is your objection to just leaving a yubikey plugged in? It eliminates most of the ways an attacker could impersonate me besides literally stealing my laptop, which is a high bar. Most people are valuable enough targets to phish or infect with malware or something, but not to plan a computer heist.

If stealing the computer is enough, someone's seriously screwed up already — it's supposed to be 2FA, not 1FA.

Re: That's not how 2FA works

#96
post #30

Earlier quoted context omitted.

I have helped literally hundreds of people setup Yubikeys across several companies. Your take is just not my experience at all. Tapping a blinking light it is much easier than fussing with a 2FA app and works when someone's phone is dead. Yubikeys in particular are near indestructible. They even work after you soak them in acetone overnight and melt the plastic off. I tried. When it says "plug in your device" you plu…

If my Yubikey gets stolen, how do I log in into my accounts? Serious question; never understood how that works.

Some other responders have given you the answer as it currently exists. They are all either inconvenient, weaken security, or both. For that reason, I would only suggest using a security key for a small number of critical services, where it's worth the extra effort to deal with the backup mechanisms.

However, a good solution for this issue is finally in the works: https://www.yubico.com/blog/yubico-proposes-webauthn-protoco...

Re: That's not how 2FA works

#97

Earlier quoted context omitted.

I think Yubikey (and similar physical solutions) will eventually gain popularity. Carrying a key is pretty much a standard practice across the globe and benefit is more than negligible because it forces physical attack versus remote/virtual.

Until keys become cloneable they will never gain popularity. Nobody wants to re-setup every site ever because they lost their laptop that they kept it plugged into, so they won't. either this means using their backup until they lose it without even revoking the original and then swearing off the entire concept while telling all their friends to do the same, or just not using hardware tokens after the first lost of ke…

I am not understanding your concern. You definitely don’t want the keys to be “cloneable”. You need at least two keys, sure, but I don’t see that as an inconvenience. And you should be using a password manager (with passwords cycled on a periodic basis) that is bound to your physical key.

Re: That's not how 2FA works

#98
post #46
post #30

Earlier quoted context omitted.

I have helped literally hundreds of people setup Yubikeys across several companies. Your take is just not my experience at all. Tapping a blinking light it is much easier than fussing with a 2FA app and works when someone's phone is dead. Yubikeys in particular are near indestructible. They even work after you soak them in acetone overnight and melt the plastic off. I tried. When it says "plug in your device" you plu…

If it's so easy why did you have to help hundreds of people across several companies set it up?

You have to (well, I guess if it isn't your job you don't have to but it's polite) help people set up anything. Doesn't mean it isn't easy. Helped my mum set up Zoom (so she could attend virtual church apparently), is Zoom not easy?

Two (three?) jobs back I had to set a bunch of people up on one time passcodes. Those seem pretty easy right? Still had to go there in person and show them.

Re: That's not how 2FA works

#99
post #95
post #89

Earlier quoted context omitted.

What is your objection to just leaving a yubikey plugged in? It eliminates most of the ways an attacker could impersonate me besides literally stealing my laptop, which is a high bar. Most people are valuable enough targets to phish or infect with malware or something, but not to plan a computer heist.

If stealing the computer is enough, someone's seriously screwed up already — it's supposed to be 2FA, not 1FA.

Stealing the computer is usually enough, as a browser cookie serves as proof of authentication all on its own. Some destructive operations require extra auth, but in terms of data exfiltration, stealing a laptop gives you everything you need.

Re: That's not how 2FA works

#100
post #40
post #34

Earlier quoted context omitted.

Could you let me know where I can buy a well supported WebAuthn key for that price? Looking at Amazon UK - https://amzn.to/3oWGYe4 - the cheapest appears to be about £30. Unless I want to risk my security to some no-name brand with zero customer support. When I got my YubiKey, it told me I had to download an Android app to make it work. So, perhaps better documentation is needed? I'm sorry you didn't like my post, I'…

Conor sold U2F Zero's for less than 10 dollars (years ago) and has a kick starter now to fund his new Solo keys: https://www.kickstarter.com/projects/conorpatrick/solo-the-f... https://u2fzero.com/ I have a few U2F Zeros and they have been working fine for years. These are simple devices. You don't need to overpay for them. Edit: Conor was building the U2F Zero tokens for $2.26 USD per unit. Read more here: https://w…

I don't think the kickstarter is relevant now. You just buy them from solokeys.com. There's been Somu since that, and Solo2 is in the offing, with plenty of storage, apparently. I bought Somu partly for convenience, and partly for the promise of PGP support, which unfortunately hasn't been added yet (though there is a development version).

In answer to the expense question, two Solo keys appear to set you back 38 quid at the current exchange rate. I don't know how they compare with HYPERFIDO, which I don't think I'd come across before.

Post reply on HN