5 ms·
A security token is an excellent concept, but usually fails when applied to 'typical' use-case scenarios. Are you military personnel who is in charge of turnin
by VA3FXP 10y ago
A security token is an excellent concept, but usually fails when applied to 'typical' use-case scenarios.
Are you military personnel who is in charge of turning the key and launching the nukes? -Excellent reason to have a key that is impossible to forge.
-Also, "key discipline" is likely very high.
Are you a paranoid nerd that wants to make sure that you cannot be compromised?
-Excellent reason to have a key that is impossible to forge.
-But what happens when you lose that security token?
i.e. "Honey! I can't find the car keys, have you seen them?"
We desperately need _BETTER_ 2FA. Bio-metrics are not the answer. I would be in favor of an implantable RFID chip or whatever 'better' tech comes around.
- Fnoord 10y ago> But what happens when you lose that security token? Pretty simple: you use your backup key to revoke the lost key. This is possible with e.g. Lastpass and Google. Of course, if the attacker logs in before you revoke the key, you are hosed, but the same would be true in your car analogy. > i.e. "Honey! I can't find the car keys, have you seen them?" With car keys, too, you have a backup key. Arguably, the physical car keys are easier to copy. > I would be in favor of an implantable RFID chip or whatever 'better' tech comes around. Nothing new, see this article from 2004 [1]. As you can read in the article, its first headline was even in 2001 (to put in perspective this is 15 to 16 years ago). Company's name is VeriChip. The problem is that the signal can be intercepted (AFAIK it doesn't use a form of OTP), and the key cannot be easily replaced/revoked. A YubiKey doesn't suffer from this issue. The issue a YubiKey has is that it can be easier lost than an implant. The YubiKey Neo ('large' version, not the 'laptop' version) supports NFC. > We desperately need _BETTER_ 2FA. Why? How? [1] http://www.wnd.com/2004/04/24179/ http://www.wnd.com/2004/04/24179/
- rthille 10y agoI'd love something like a Yubikey Neo (NFC) with a fitness band type form factor (that I can shower/swim with), and an intention indicator (button of some sort) before the NFC would respond.
- Fnoord 10y agoRight now I use a Pebble smartwatch (which I use for fitness, too) with Bluetooth 4 to unlock my Android phone. Not very secure since (as you put as well) I don't verify the unlock via my smartwatch, and I'm not sure about impersonating Bluetooth 4. Then again, I'm not sure if NFC (RFID) can be impersonated, either. And, if yes, how feasible it is.
- userbinator 10y agoThat begs the question, what if you lose your backup key too (it's far less frequently used, adding to the possibility) or don't have one because it would decrease security? Here is where car analogy stops working.
- Fnoord 10y ago> That begs the question, what if you lose your backup key too (it's far less frequently used, adding to the possibility) or don't have one because it would decrease security? Here is where car analogy stops working. What if you lose the backup key to your car? You're can break a window to enter, but a modern car won't start easily because of the lock on the steering wheel. Make sure you don't store both keys at the same place. Make sure one is stored at a secure place, while the other one is securely attached with you. A secure place to store a key is a fireproof safe, or a notary.
- na85 10y agoIn a real pinch, I can pay a locksmith. Can you do the same with crypto? The procedures to maintain access to your car aren't really sufficient.
- Fnoord 10y agoA non issue, PEBKAC. If you're afraid you lose both your main key as well as your backup key at the same time before you were able to reinstall another backup key you can ensure you have more than 1 backup key, and/or (re)consider where you store your backup key(s). Also, it depends on where you are using the YubiKey. If its an online service you may be able to identify yourself via alternative ways. If its your FDE, you're hosed. Or you have backups. Either way, the above still applies.
- nickik 10y agoWe don't need better 2FA, we need better 1FA. Biometrics are not the answer for that either, but rather new protocols that are independend of the mechanism you use. That exactly what the FIDO protocols are trying to do. You can use you shitty local fingerprint sensor as a authenticator but you will still get better security agains everything exept if somebody steals your phone. Phising is the biggest problem, it needs to be solved. We can do it in the first or the second factor. People either need to move to U2F or they need to move UAF on the first factor. This is really the only hope.
- Fnoord 10y ago> Biometrics are not the answer for that either Biometrics are a way to identify a user (and establish a username); not a form of authentication or replacement for a password. This is because biometrics cannot be replacement, while they can be copied or mimicked. 1FA is theoretically possible without a password, with a form of OTP.
- lightedman 10y agoBiometrics SUCK. I spend many days a month digging rocks. My finger prints are rarely intact enough for a fingerprint reader to capture them and read them.
- Fnoord 10y ago> Biometrics SUCK. As do [secure] passwords. Which I'll demonstrate below. > My finger prints are rarely intact enough for a fingerprint reader to capture them and read them. Scan multiple fingers. Use different biometrics such as a photo of your face, or your eye. Remember, biometrics are meant as username replacement, not authentication (e.g. password-based); ie. so you don't have to type 'lightedman', not 'ethically-rage-retake-unlined-wrangle-lapel'.
- SEJeff 10y agoAnd yet the original point still stands, which is biometrics are terrible passwords. I still agree with this timeless article on biometrics (fingerprints for this article, but all biomentrics in general) are excellent usernames, but terrible passwords: http://blog.dustinkirkland.com/2013/10/fingerprints-are-user-names-not.html http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
- pfg 10y ago> But what happens when you lose that security token? It's really not that big of a problem, at least in the "paranoid nerd" context. Just have backup keys that your users can print out and keep in a safe place. Or have more than one U2F device - most implementations I'm aware of allow users to register more than one device. Of course, for most applications, there'd still be the usual support backdoor. That's definitely a problem not quite as easy to solve.
- sowbug 10y agoNot disagreeing with your comment, but what do biometrics have to do with this article? I don't think Yubico does anything with biometrics, and these devices definitely don't have any such capability. Moreover, U2F already is awesome 2FA (better than _BETTER_). Fast and unphishable. Buy a few of these, keep one on your keychain, one on your desk at home, and a backup locked in your safe, and you're all set. We use the USB-A version of these things extensively at my company, and they're unbelievably convenient.
- eridius 10y agoI'm not the OP but I assume they brought up biometrics because that's something you can't forget and leave at home (like you can with a Yubikey attached to your car keys).
- sowbug 10y agoI get it, now, thanks. OP used biometrics as a strawman, and I misinterpreted the use as a reply to a (nonexistent) point in the original article.
- chiefalchemist 10y agoFwiw I wear my key around my neck. It only comes off the shower. Routine is the key to retention
- daurnimator 10y ago> I would be in favor of an implantable RFID chip or whatever 'better' tech comes around. Like a vivokey? http://vivokey.com/learn-more.html http://vivokey.com/learn-more.html
- shpx 10y agoWhy not just wear a ring? Seems like the main reason is so that the guy who made it can call himself a transhumanist and say futuristic things. Watch him put his phone to his wrist. If it was on his finger he wouldn't have to take the phone out of his hand. Is that thing glass? How is he not worried about it shattering when he falls? I found http://nfcring.com/ http://nfcring.com/ but macbooks can't do NFC, otherwise I'd preordered one. I also learned that NFC is RFID at 13.56 MHz.
- daurnimator 10y agoThe vivokey has a secure element: you can keep RSA keys on it and use it like a yubikey. Notably, it's the first NFC 4096 bit capable device I've seen (Yubikey Neo is max 2048bit; Yubikey 4 doesn't have NFC).
- rwmj 10y agoPractically speaking, I've been using a yubikey plugged permanently into my laptop for many years, and it works fine. I use it to authenticate to my work VPN (with a password as second factor). The only downsides are: one fewer USB port, and the green light on the yubikey which is permanently lit.
- syrrim 10y agoYou've made a great list of the downsides, perhaps you could at some point list the upsides? A yubikey you don't move around, and that you don't take extra steps to ensure the security of, seems no more secure or useful than a cert file on your hard drive.
- tjohns 10y agoUnlike a cert file, a hacker can't steal the keys in a Yubikey if the machine is compromised. Same reason why many enterprises prefer using TPMs for storing machine certs. The advantage of a Yubikey over a TPM in this case is that the Yubikey requires a physical tap before it'll sign a request, which prevents certain MITM attacks.
- Steltek 10y agoIf I understand correctly, you must touch the Yubikey to reply to a second factor request. Simply being present in the USB port is not sufficient to utilize its credentials.
- spilk 10y agothe PIV and OpenPGP apps don't seem to require the physical interaction, but do require a PIN entry (just like a traditional smartcard).
- rwmj 10y agoAs others have said, you have to touch the yubikey to get it to generate a one-time password (it acts like a USB keyboard). The yubikey is one factor, the VPN also requires a second factor (memorized password). These are concatenated so you type the password without pressing the enter key, then tap the yubikey (which "types" the OTP + enter key). This process works in web forms, shells, etc. Could hardly be simpler. If the laptop is lost/stolen, I can deactivate the token.
- chiefalchemist 10y agoMoi? I'd rather buy ten passive backup keys than implant an RFID key that puts out a signal that never turns off. At that point you're robbing Peter of pay...Well...Um...Big Brother.
- userbinator 10y agoIndeed it is always important when considering security, to look at the other side and balance the risk of someone else gaining unauthorised access with you possibly losing access forever. Everyone wants "unbreakable" encryption, but unfortunately it seems very few consider the possibility of themselves losing the key --- perhaps it is because locks in the physical world are not quite as strong as good data encryption, and can be easily overcome with locksmiths and the like.