13 ms·
Soft U2F: A software-based U2F authenticator for macOS
- Rjevski 9y agoWhat's wrong with client certificates? Instead of reinventing the wheel they should've just used those which would've given browser vendors a reason to improve their UX regarding client certs.
- ptoomey3 9y agoThat is roughly all U2F is. It is a per-origin key pair that is registered with each site and used to sign challenges. At some point browsers themselves might implement something like Soft U2F, at which point, they basically will have "improved the UX of client certs".
- Rjevski 9y agoThe advantage of client certs over U2F is that client certs use the same proven mechanism your browser uses to verify the server's cert, and can even be handled by the web server. It's also seamless for the user - if needed you can be logged in right from the first request. U2F needs to be implemented over the top in the app itself and the login process is at the minimum two steps (no way to login from the first request).
- wmf 9y agoMost sites can't sacrifice all their users in the short term for the good of the Internet long-term.
- Freak_NL 9y agoWith hardware U2F the benefit lies in not having the private key available on the client device at all. That means that copying it is impossible (without dismantling the key and using quite advanced equipment to attempt to read the private key). With software U2F I think you are right; client-side certs just work, now, in all major browsers. Installing them is a hassle, but it can be managed with good documentation (we use client-side certificates for authentication at the moment). Personally, I don't think software U2F should exist outside of development and testing scenarios.
- hdhzy 9y agoWell you can have client certificate on hardware. Some hardware even has attestation built in [0] so you can be sure that the private key is non exportable. PIV based smartcards do not require external drivers on most modern OSes. [0]: https://developers.yubico.com/PIV/Introduction/PIV_attestation.html https://developers.yubico.com/PIV/Introduction/PIV_attestati... U2F is designed for only one algorithm and allows a lot of optimizations (e.g the private keys are not really stored on the device but rather generated from master seed and origin). That's why they are substantially cheaper than PIV devices.
- hdhzy 9y agoClient certificates are best from security perspective but lack UX (this could be fixed) and are not designed with privacy in mind. U2F on the other hand generates unique pair of keys for each origin. By default.
- madamelic 9y agoCan someone explain how this is an improvement on phone-based, non-SMS 2FA? This solution seems ripe for exploitation by putting your passwords (if you store your passwords on your computer) and 2FA on the same machine.
- crummy 9y agoThe improvement is accessibility. It's less secure than physical 2FA but more so than just 1FA. As the article says, "for many, the security of software-based U2F is sufficient and helps to mitigate against many common attacks such as password dumps, brute force attacks, and phishing related exploits."
- nevir 9y agoIt's really not that much less secure than physical 2FA: I'm willing to bet that most people just leave their hardware key in their laptop at all times. (where "most people" ends up being corporate U2F users, who are probably given YubiKey Nanos and the like) At that point, your laptop is basically your 2nd factor - which this software is pretty similar to.
- petee 9y agoBut even if you leave it in, everything is still protected in hardware, and in addition, malware can't trigger a physical presence button push...so, it is in fact significantly less secure...
- djcapelis 9y ago> malware can't trigger a physical presence button push It kinda can, it just needs to trigger a dialog the user thinks looks legit. Or easier, just stay resident until the next time the user pushes the button. Don't get me wrong, U2F has benefits, but it's not invulnerable to malware designed for it. You want real system level protections to back it up and most users aren't running on operating systems that can really cash the check you're trying to write with that threat model.
- bugmen0t 9y agoYou don't really[1] need to install this, if you're using Firefox. Just set the prefs 'security.webauth.u2f' and 'security.webauth.u2f_enable_softtoken' to true. [1] (Unless you need the token to live in your Mac OS keychain, instead of the Firefox profile directory.)
- mastahyeti 9y agoMy understanding is that the FF softtoken was intended to be temporary while they worked on their HID support. That might not be the case any longer though.
- ilikepi 9y agoYeah, the software token was only intended for testing purposes.[1] HID support is supposedly a goal for later this year.[2] There is also a third-party(?) add-on for hardware token support[3], but apparently it will stop working with FF 57 as it not was not written for WebExtensions. (Disclaimer: not affiliated with Mozilla; I just check in on bug 1065729 every so often.) [1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1065729#c262 https://bugzilla.mozilla.org/show_bug.cgi?id=1065729#c262 [2]: https://wiki.mozilla.org/Security/CryptoEngineering#Web_Authentication https://wiki.mozilla.org/Security/CryptoEngineering#Web_Auth... [3]: https://addons.mozilla.org/en-US/firefox/addon/u2f-support-add-on/ https://addons.mozilla.org/en-US/firefox/addon/u2f-support-a...
- scott00 9y agoDoes this actually work for you? I could never get that to work. (Firefox 54 on Windows)
- mtgx 9y agoThis isn't also backed-up by SMS, is it? Because the majority of U2F-supporting services seem to be doing that - even Google (and for its own Google Prompt, too).
- mastahyeti 9y agoYou still have to configure TOTP (SMS or App) 2FA before you can add a U2F device. That might change in the future.
- cimnine 9y agoYou can disable Google SMS 2FA anytime.
- ptoomey3 9y agoAnd the same is true on GitHub. You can use app based TOTP without SMS.
- kbenson 9y ago> even Google (and for its own Google Prompt, too). Just for iOS, or for Android as well? Is Android intercepting Google sourced SMS messages so it doesn't appear to be SMS, or are you referring to the iPhone experience?
- atonse 9y agoTo Github people: I ordered your yubikey token but stayed away from U2F out of fear that I'd be locked out if I lost the hardware token. But I didn't realize you could setup U2F and TOTP as a backup.
- sowbug 9y agoYou can also order as many of the U2F devices as you wish and associate them all with any number of accounts. Yes, they do cost money, but the cheapest today is $10 shipped on Amazon. Even if you prefer the ergonomics of the more expensive ones, it's fine as a backup you keep locked in a safe at home.
- chaz6 9y agoI do this, but the downside is, if I lose one I have to go through each service removing both tokens (because some services do not tell you which is which) then adding the existing (not lost) token with the new one. This is making me wish for OpenID again where I nominate my authenticator of choice so I only have one place I need to maintain my tokens.
- tptacek 9y agoNot only can you do this, but the major services won't even let you set up U2F without a backup factor. The best current Google auth stack, by the way, is: 1. U2F 2. Phone-based authenticator app (TOTP) 3. Password-manager password 4. Printed codes 5. DISABLE SMS. (Google forces you to enroll in SMS to turn on 2FA; you can simply delete your phone number after enrolling everything else).
- rcthompson 9y agoThank you for letting me know that SMS authentication is not mandatory for Google accounts! I assumed it was for the reason mentioned in your comment.
- atonse 9y agoFor some reason I made the wrong assumptions. Thanks for the clarification. I'm going to activate that U2F key asap, and also disable SMS for my google account.
- milkshakes 9y agothis would be great if it were linked to touchbar fingerprint sensor
- mastahyeti 9y agoIt is :-)
- philip1209 9y agoUntil Yubikey releases a USB-c version of their nano, I think I'll use this. Since I've had to transition to a keychain U2F device instead of one I can leave in my laptop, I find myself using it far less.
- sowbug 9y agoI'd expect the U2F protocol to be built into secure elements on laptops before a Type-C Nano comes into existence. USB-C ports are too precious to keep them filled all the time with an authentication device, and there doesn't seem to be enough room in the male side of the Type-C coupling to allow the necessary circuitry to exist in a slim form factor. Both these problems are solvable, but meanwhile secure elements are already shipped with many laptops. (An assumption of this comment is that the Nano is kept semi-permanently in the laptop port. That's what the Nano is indeed designed for.)
- drodgers 9y agoHonestly, I don't know why Apple don't implement U2F on the secure enclave (activated via the TouchId sensor); it seems like such an obvious move. Maybe they're trying to get iCloud and Safari support all ready to release at-once?
- cormacrelf 9y ago¡Hola 2018!
- hdhzy 9y agoWow, great idea! I think Web Authentication will slowly make U2F obsolete, in a sense that U2F will become one of many authentication methods, others could also be implemented. Checking WebAuth specs one can see references to Android attestation, TPM attestation so generally secure hardware elements. Implementing a U2F solution would require emulating USB exchange I guess. Of course U2F still has an advantage that you can take your token and authenticate on a different device but unfortunately newer Yubikeys do not support U2F over NFC and there are not so many other solutions.
- djrogers 9y agoThis seems a little restrictive if it doesn't have some sort of 2FA alternative, like a mobile TOTP app or something. I'd hate to be locked out of any accounts for losing my MacBook, or to be unable to use the accounts from mobile or a different platform. As a secondary/simpler 2FA alternative I like it, but the description here doesn't do much to explain how to get around the problem of only having this available on my macs.
- elchief 9y agothe solution for actual U2F tokens is to buy 2 and put one in a safe deposit box. not sure what the solution is for software version
- philip1209 9y agoIn general, U2F doesn't work on iPhones - so most sites offer multiple methods of secondary authentication (including Github, Facebook, and Google). So, it is a bit of a convenience - but it also more secure because it matches hostnames.
- ndm 9y agoTOTP via SMS or apps is required to set up a u2f key on GitHub.
- lisper 9y agoI tried it but it didn't work for me. I'm running Mavericks. Do I need to reboot or something?
- ndm 9y agoAre you triggering U2F challenges by visiting sites that support u2f? Opening the app doesn't do anything.
- lisper 9y agoYes. The configuration I was using (Yubico test site on Chrome) works against hardware tokens. Just for context, I'm pretty well versed in U2F. I actually sell a U2F token of my own (https://sc4.us/hsm https://sc4.us/hsm) and I've published a serverless U2F test harness (https://github.com/rongarret/u2f-test https://github.com/rongarret/u2f-test).
- mastahyeti 9y agoI've only tested on Sierra, so I'm not terribly surprised that this doesn't work. Would you mind opening an issue so I can help debug? https://github.com/github/SoftU2F/issues/new https://github.com/github/SoftU2F/issues/new
- lisper 9y agoDone.
- bdcravens 9y agoIf you're already into Bitcoin the hardware wallets also can be used for U2F
- scott00 9y agoAny plans for a Windows version?
- mongol 9y agoU2F adoption seems quite slow. Google were in early, and later github and Dropbox. But since then? Feels like nothing happened.
- csomar 9y agoI think it is attack-driven. Most bitcoin wallets/exchanges have 2FA/U2F because it is a must given the value at stake. If you are running a forum board, you probably don't care much neither are your users going to bother.
- jack12 9y agoAside from the obvious reason why (iOS support looks unlikely to ever happen), I imagine seeing the list of supported browsers read nothing but "Chrome" discourages implementation too. Though U2F's javascript API situation makes a lack of adoption a bit of a mixed blessing. Because sites need to include browser-specific code to access a browser's U2F support, that means any site adding support for Chrome right now will have to go back and modify their code to add support for Firefox when it comes, etc. (From the spec: "RPs [Relying Parties, i.e. web pages using U2F] interact with the FIDO client through a MessagePort [WEBMESSAGING] object. [...] This specification does not describe how such a port is made available to RP web pages, as this is (for now) implementation and browser dependent.") Google and Yubico provide an example wrapper around the Chrome-specific method for getting access to Chrome's U2F messageport (at https://github.com/google/u2f-ref-code/blob/master/u2f-gae-demo/war/js/u2f-api.js https://github.com/google/u2f-ref-code/blob/master/u2f-gae-d... in the function u2f.getMessagePort), but the wrapper gives up if it's not running in Chrome (the else branch just tries hitting the old Chrome extension by hardcoded chrome-extension:// URL). Even if Google's wrapper someday adds support for other browsers, every site will need to update its copy of the wrapper before that site will support the other browsers. If very many sites were adding U2F support right now, I suspect a lot of them would remain Chrome-only even as more browsers added U2F support. Maybe if adoption only happens after more browsers already have their U2F support available, more sites will end up supporting those browsers than if it was getting adoption right now.
- bb88 9y agoFacebook recently supported it too. Here's the problem. These are the 2nd factor solutions off the top of my head. 1. Yubikey 2. Duo 3. TOTP/Google Auth 4. SMS 5. Fido U2F 6. JavaCard 7. RSA SecurID 8. Perfect Paper Passwords. Sure U2F is technically better, but many of those are 'good enough' and make people lots of money.
- ianopolous 9y agoI've been looking into 2FA on Github and I don't understand why you must have either SMS or TOTP (typically a mobile app) as the primary second factor. Why not let users go straight to a yubikey? I don't want my mobile involved in the process at any point. You also can't remove the TOTP factor once you've added a yubikey, so yubikeys are 2nd class citizens, despite being much more secure.
- ptoomey3 9y agoThe primary reason is exactly the reason you cited (u2f support is not ubiquitous across browsers..especially mobile). We may consider allowing folks to use u2f exclusively in the future, but we started conservatively given the already risky proposition of account lockout with regular 2FA.
- ianopolous 9y agoThank you for clearing that up. Personally, I'm more likely to lose my phone or have it brick itself (happened to my previous phone) than to lose a yubikey.
- re1man 9y agoExtension version with similar functionality: https://chrome.google.com/webstore/detail/keyless-u2f/bhgbpfmmjenlapdolpeijifcedhcogne https://chrome.google.com/webstore/detail/keyless-u2f/bhgbpf.... Works with Mac + Windows. Amazing to see more soft solutions for U2F.
- petee 9y agoThis seems misguided - it is watering down a decent system simply to appease and attract people too cheap to buy tokens; if 2fa is something that is so important to you, and you need it, just buy the damn tokens! A vague comparison, would be me selling pre-printed 'random' passwords on paper because a user generating their own was 'too difficult' IMHO, soft token u2f is only useful for testing, development, and personal entertainment
- m-j-fox 9y agoBut notice the software is only for Mac. So it's for people who are too cheap to spring for a $10 key but drop $1k on a laptop. Go figure.
- deleted 9y ago[deleted]
- pfg 9y agoMalware running on your computer is a game-over scenario even with hardware tokens. The main difference here is that you'll need to revoke the device key after a compromise. Password reuse and phishing are probably the most common threats users face. This addresses both with a (for most users) negligible security trade-off. If it increases U2F adoption, I'm all for it. I'd like to see U2F (or webauthn) become a browser/OS feature, backed by TPMs or things like TouchID, but this is a good first step.
- ptoomey3 9y agoJinx :-)
- ptoomey3 9y agoWhat is the attack scenario you feel a hardware token protects you against that a software token will not (for the use cases U2F was designed for)? Sure, hardware tokens prevent malware from actually lifting your private keys. But, to steal your software private keys you likely need malicious code running on your computer. And, once an attacker has that, it is largely game over for all intents and purposes anyway. They can ask your hardware token to sign bogus requests, steal your passwords, etc. Sure, with a hardware token you can wipe your machine and feel semi-confident that you get to keep your private keys. But, really, once your machine has been compromised and you wipe it, setting up new private keys sounds like a wise practice regardless. I'm not arguing that hardware tokens have zero use. But, for most users, the attack model where hardware tokens shine is likely not of value to them.
- cbhl 9y agoI'm surprised they're willing to trust a mouse click on a notification. (Can't that be simulated by malware by using the Accessibility APIs?) I was expecting a U2F authenticator that wanted a Touch ID touch first.
- pfg 9y agoMalware is a game-over scenario either way. It can simply steal your session keys or send requests from your browser with an active session. That said, there seems to be some sort of TouchBar integration[1]. It doesn't currently store the keys in SEP, but that might become an option at some point[2]. [1]: https://twitter.com/mastahyeti/status/889546786221678592 https://twitter.com/mastahyeti/status/889546786221678592 [2]: https://twitter.com/mastahyeti/status/889548782035124224 https://twitter.com/mastahyeti/status/889548782035124224
- cntlzw 9y agoU2F is great and you can get a physical device for around $15. I wish banks and such would adopt U2F sooner than later. They could just sent U2F tokens as giveaways. Big downside: Apple and Microsoft. They don't support it in their browsers. No browser support, no U2F.
- bostand 9y agosafari and edge users are a tiny minority. Most security aware people use chrome anyway.
- ohthehugemanate 9y agoReally, you think security aware people use Chrome? The security aware people I engage with avoid it. The baked in data collection and telemetry are a concern for them. Some of them even remember specific problems, like that time it turned out Chrome was listening on your mic all the time, and sending the a audio back home. The security conscious people I know use Firefox or chromium. Of course, your point stands: no one's using safari or edge. :)
- dogma1138 9y agoYou always have chromium also don't confuse security awareness with privacy concerns. Chrome is more secure this means that you have less of a chance having your data compromised including any and all data on your machine by an unknown 3rd party. Since Chrome's data collection is known it can be incorporated into a simple threat model. You know what is collect and who collects it, most security aware people will be OK with Chrome collecting some metrics that in all fairness are likely to be collected anyhow unless they block every JavaScript and Cookie on the planet, do no use any Google service or a service that uses GA in exchange for not having to worry about their browsers being pwned.
- ekingr 9y agoAny chance iOS Safari enables it once Apple opens its NFC APIs in 11?
- 9y ago
- jdeibele 9y agoSomewhat disconcerting to see this in Chrome: Attackers on github-production-release-asset-2e65be.s3.amazonaws.com may trick you into doing something dangerous like installing software or revealing your personal information (for example, passwords, phone numbers, or credit cards).
- mkj 9y agoThe kext shouldn't be necessary for a Safari and Firefox plugin. Is it just there to fake a u2f usb device for Chrome?
- chaz6 9y agoThe benefit of U2F to me is that it is a hardware token. I would never use a software token when I can use a hardware token.
- sly010 9y agoI don't see anyone mentioning that Google won't allow you to use U2F anywhere but on Chrome. E.g last time I tried I couldn't log in using Firefox even if I installed the plugin. [0] [0] https://productforums.google.com/forum/#!topic/gmail/IwKFuNh0mh8 https://productforums.google.com/forum/#!topic/gmail/IwKFuNh... Edit: link
- exabrial 9y agoIt'd be awesome to see keybase integration