7 ms·
I'd like to try to answer some common questions I see here: - Q: Doesn't passwordless mean single factor? Isn't that insecure? A: It could mean single- or two
by emlun 8y ago
I'd like to try to answer some common questions I see here:
- Q: Doesn't passwordless mean single factor? Isn't that insecure?
A: It could mean single- or two-factor. FIDO2 and the new YubiKeys support an on-device PIN that isn't shared with the server, like conventional smart cards. This allows the key to act as both "something you have" (the key itself) and "something you know" (the PIN for the key). The PIN is optional, though, so both the single factor and two factor use cases are possible.
- Q: Is this Azure/Windows/AD only?
A: This post highlights the partnership with Microsoft and the integration with their products, but FIDO2 is not Microsoft-only (and Yubico will not be the only key vendor). CTAP2, once finished, will be published as an open standard like U2F, and the accompanying Web Authentication API [1] (WIP) is an OS-agnostic W3C standard enabling the same features in browsers.
[1]: https://www.w3.org/TR/webauthn/ https://www.w3.org/TR/webauthn/
- Q: Will I need a new YubiKey?
A: For passwordless (PIN) login, yes. However, existing YubiKeys with U2F support will be usable as a 2nd factor in Web Authentication, and sites that currently use U2F can upgrade to using the Web Authentication API without needing their users to re-enroll their keys.
Full disclosure: I'm a Yubico engineer and one of the editors of the Web Authentication spec.
- ahelwer 8y agoWhat's the deal with lost yubikey user workflow? Rely on individual websites to give you a one-time recovery passcode that you then have to input into every website? I can't believe I'm taking UX cues from cryptocurrencies, but what about providing the user with a seed for the yubikey private key they can back-up offline then reinstall in a new yubikey? P.S. just ordered a yubikey security key, excited to add this additional layer to my own personal byzantine security labyrinth. Or maybe simplify it, who knows!
- closeparen 8y agoRecovery codes or 2 Yubikeys.
- krrrh 8y agoYou can use Trezor or Ledger hardware wallets for U2F with recoverable seed words. Even if you go with a Yubikey, which has a better form factor, one of these is a pretty good backup device since they can be further backed up to paper.
- girvo 8y agoI bought two Yubikeys and have one in a safe (mainly so I don’t lose it). This isn’t perfect though, as not all places support multiple keys :(
- emlun 8y agoIt's still a largely unsolved problem, unfortunately. Enabling private key backup comes with a suite of nasty problems like what it means for device attestation and how to guarantee that a key hasn't been cloned in transit. Our best recommendation right now is to have a backup key, but it still means you have to register it everywhere in advance and then go to each site to revoke the lost key. At least Web Authentication platform credentials should let you have multiple authenticators without having to buy an extra YubiKey.
- francislavoie 8y agoDo you have any plans to release server code (I'm mainly concerned about PHP) for CTAP2/WebAuthn support? I really appreciated having access to a reference implementation to handle the data from the client for U2F. CTAP2 looks significantly more complex, and I'm somewhat worried about complexity of implementing it correctly based on the spec.
- emlun 8y agoWe have C, Python and Java libraries released right now, all of which are beta WIP as we don't yet have any users who can inform the API designs from real world use cases. https://github.com/Yubico/libfido2 https://github.com/Yubico/libfido2 https://github.com/Yubico/python-fido2/ https://github.com/Yubico/python-fido2/ https://github.com/Yubico/java-webauthn-server https://github.com/Yubico/java-webauthn-server
- StavrosK 8y agoI'm thinking of writing a Django-webauthn library (although I'm not sure if it would just be simpler to fork django-u2f). Would the Python library help at all? It looks like it's for USB communication and not for general helpers around signing/authentication/etc.
- emlun 8y agoIt's mostly for host-authenticator communications, yes, but it it includes a couple of helpers for verifying signatures. But you're right it's not a full-featured server library at this point.
- parent5446 8y agoIs there word on whether Yubikey 4 models will support FIDO 2? Or do we have to wait for a new model?
- emlun 8y agoThey will not support FIDO2, but they do support U2F which is compatible with a subset of the FIDO2 features. Specifically, they don't support PIN or username-less login, but they CAN be used as 2nd factors (emphasis on the 2) in addition to conventional username+password login.
- datalog19908 8y ago> he new YubiKeys support an on-device PIN that isn't shared with the server Doesn't this PIN become a master password for all the websites at that point?
- not_that_noob 8y agoThat’s really the flaw of single sign-on and Webauthn - that one key now unlocks the kingdom.
- zaarn 8y agoI don't see that as a flaw really. It's not different to having a password manager, with proper WebAuthn atleast. What you do is you take this key that unlocks the kingdom. And then you keep it safe. Unlike before there isn't 20 keys that unlock parts of the kingdom that might lead to unlocking other kingdoms via roundabout ways. Your attention for security can be focused on a single key. The average users will be much safer if we force them to only have to remember one single password that can be securely used for everything without the usual drawbacks (that's why security people recommend password managers)
- not_that_noob 8y agoThe flaw stems from the fact that an attacker can thru social engineeung acquire that root crendential (password or biometric or token). Once they have it, they can clean out all your banking, stock and home equity line accounts in one sweep. You as a user may not know that credential is compromised - maybe it was a key logger, maybe it was social engineering the cell phone provider to port your number and then qualify their phone with an sms token. You don’t know when that happened - you just see empty accounts. With personal password managers, no third party is issuing tokens for access - just you. So it’s unlikley to be chosen for an attack - because it’s too hard for the attacker to acquire the credentials for access without detection.
- Freak_NL 8y ago
- not_that_noob 8y agoA PIN is really a numeric password. It has all the same flaws - compromise risk (say via social engineering) and the risk of forgetting and needing it reset. So the ‘passwordless’ option here is either rename the password to PIN or eliminate it to provide single-factor login. The latter is a dream for smart attackers, since there is always some social engineering route they can use to acquire a legit token.
- icebraining 8y agoNot all the same flaws; malware will have a much harder time recovering it. Also, you can use a regular password to "semi-authenticate" with the call center of the service and try to get them to disable the second factor, but this PIN is only useful with physical access to the device.
- emlun 8y agoYou would have been right if not for the important keyword "on-device". The PIN does not risk being exposed by server breaches, because it's never on the server. Yes, it can be extracted via clever con artistry, but that's true for _any_ "something you know" factor including conventional passwords. The whole point of multiple factors is that they have _different_ sets of weaknesses. Also: unlike a shared secret like a password you share _everywhere_ (and let's face it, most people do), an on-device PIN can be changed in a single place should it ever be compromised.
- closeparen 8y agoThe key feature of security tokens is that it’s very difficult to extract or manipulate their internal state. A short numeric PIN enforced by a token is much more secure than a high-quality password whose hash is stored in a database: the token can rate limit PIN attempts and zeroize itself if too many attempts are made.
- teknopaul 8y agoDoes it identity you as the same person to two different websites? I.e. Is it for building up advertising profiles like google oor facebook logins?
- Freak_NL 8y agoThe FIDO U2F and WebAuthN standards explicitly address this issue, because it is a valid concern. No, your key cannot be detected as being the same key on website A and B. Undoubtedly the same holds true for these Microsoft services.
- emlun 8y agoWhat Freak_NL said. No, there is no globally correlatable identity, and it won't be possible to either create or authenticate credentials silently. Browsers will show confirmation popups and YubiKeys will start blinking to prompt for touch confirmation.
- consp 8y ago> A: It could mean single- or two-factor. FIDO2 and the new YubiKeys support an on-device PIN that isn't shared with the server, like conventional smart cards. This allows the key to act as both "something you have" (the key itself) and "something you know" (the PIN for the key). The PIN is optional, though, so both the single factor and two factor use cases are possible. No, since passwordless login is available, the lowest denominator applies: single factor. Despite all your efforts it will most likely be possible to perform a passwordless login even when password is required in a few years (as these things get broken). The something you know is useless, as it can be ignored. And because it can, it will. Either by force, by negligence or by laziness.
- emlun 8y agoMaybe I misspoke - by "optional" I meant "optionally required". The server can require the use of a PIN - and although the PIN verification is done client-side, the authenticator (YubiKey) sets a bit in the signed response to indicate whether PIN was used. The server can then verify the authenticity of the bit if it trusts the authenticator's attestation certificate. It's also allowed for authenticators to always require PIN even if the server doesn't, but the current YubiKey obeys the server's preference. But yes, there will of course be bugs. But that is also true for password logins, so I don't see it as a particularly convincing argument.
- Yizahi 8y agoDo you have any information when any major websites will (may?) support U2F in Firefox? Google, FB etc. Is there some issue with Firefox U2F implementation maybe? Thanks.
- StavrosK 8y agoGithub works fine with U2F in Firefox, I think the problem is just that Google is doing browser detection rather than capability detection. (Of course they do, since they want to underhandedly promote their own browser).
- emlun 8y agoFrom what I understand, Firefox doesn't implement the whole U2F spec, and Google and Facebook use some of the features (appID facets) FF left out. However, Firefox, Chrome and Edge all plan to implement the whole Web Authentication API.
- polack 8y agoI wasted so much time and energy on implementing U2F for a web application, writing server side lib and making the javascript framework compatible with the horrible js-hack that's available for U2F support. It was all in vein; the browser support is still horrible, no one want to use it and it's not possible to use on mobile. How can you make a security solution that doesn't work on mobile? Making a new "Web Auth" standard is a huge mistake, and I will not fall into that trap again.
- danudey 8y agoI ran into this with GitHub. I ordered a YubiKey, got it all set up with GitHub, and… never use it. Because it's not supported on mobile or in Safari. If anything, the web needs technology that allows browsers to present secure third-party auth to web services (e.g. through TouchID, the way that Apple Pay works on Safari and Mobile Safari).
- asaph 8y ago> Q: Doesn't passwordless mean single factor? Isn't that insecure? > A: It could mean single- or two-factor. FIDO2 and the new YubiKeys support an on-device PIN that isn't shared with the server, like conventional smart cards. This allows the key to act as both "something you have" (the key itself) and "something you know" If "something you know" is physically stored on "something you have", doesn't this make "something you know" completely moot?. Please explain how this doesn't simply reduce to "something you have". In other words, if someone steals your Yubikey, can they login as you without knowing anything additional?