8 ms·
YubiKey comes to the iPhone with Mobile SDK for iOS and LastPass support
- zaroth 8y agoIf I’m authenticating with “something I have” then why not use the iPhone itself which also happens to add a layer of “something I am” (FaceID) as well as easily supporting entry of something I know (PIN or password). Using a hardware token to authenticate to an app on an iPhone makes about as much sense as.... sorry, it makes absolutely no sense at all. I trust the secure element on the iPhone a lot more than I trust the hardware on the Yubikey. The days are numbered for this whole idea of a separate piece of hardware USB/NFC to do authentication. If I’m adding a “something I have” factor to my authentication flow (or even making it the only factor) it’s going to be the phone hardware itself, not an extra dongle thing I have to carry around. FIDO’s upcoming CTAP unfortunately is going about it the wrong way, IMO. I don’t want to have to establish NFC or Bluetooth from my iPhone to my desktop to enable me to use my iPhone to authenticate on my desktop. It’s entirely unnecessary since both devices are already online. They are designing for a corner case which makes the primary case too complicated.
- jpdb 8y agoDo iPhones allow access to the underlying TPM devices? I personally don't believe things like Google Authenticator are a good "something you have" second factor as the "something you have" is just a string stored in a sqlite database. Much easier to covertly copy that than a hardware key where the string is burned into the key.
- rightos 8y agoI don't think theres much value in "something you have" so much as there's value in "approving this authentication via another device". Adding an additional device to compromise running an entirely different platform makes attacks much more difficult, even if we're talking about a poorly secured Windows machine and outdated Android phone. Enough to make you effectively invulnerable to almost all non-targeted attacks which will only breach one side or the other.
- jakobegger 8y agoYes, iPhones allow storing data that can’t leave the device. Otherwise OTP apps would be pointless. I don’t know the details, but some apps use it to store OTP secrets. Eg. if you use the DUO app, your secrets will be backed up, but they can only be restored on your phone. (was quite a hassle to reset 2FA on all the websites after my phone was replaced in warranty repair) Not sure what Google authenticator does.
- deleted 8y ago[deleted]
- rightos 8y agoAre iOS Authenticator apps actually calculating OTPs on the Secure Element? Is there a way to execute arbitrary code on it? If not, they have to pull the keys off to the main CPU where they're open to attack like anything else. Still secured as private app data, still mostly protected, but an attacker with a jailbreak could still dump them. I know for a fact I can dump Google Authenticator keys from my Android device with root as I'm able to back it up and move it to another device. Theoretically on most Android devices even there's a secure enclave available that could do it, yet I haven't seen any apps use it. Most of the benefit of OTPs really comes from approving on a secondary device rather than protecting the keys to an absolute degree though, so this is probably of little concern to most users. In fact it may provide a convenience benefit, I like being able to backup and move my keys, without that I probably wouldn't use 2FA at all.
- moduspwnens14 8y agoUsing the secure enclave, you (as a developer) can have it generate a private key you'll never be able to get and then ask it to sign / encrypt (symmetrically) arbitrary things for you. https://developer.apple.com/documentation/security/certificate_key_and_trust_services/keys/storing_keys_in_the_secure_enclave https://developer.apple.com/documentation/security/certifica... AFAIK that means it'll take more than a jailbreak to get to them, although I don't know if OTP apps are using that capability or not.
- 8y ago
- donarb 8y agoGoogle Authenticator is not a password storage app. It produces time-based hashes that expire every 60 seconds. https://en.wikipedia.org/wiki/Time-based_One-time_Password_algorithm https://en.wikipedia.org/wiki/Time-based_One-time_Password_a...
- RKearney 8y agoOP never claimed that it was. They were discussing the second factor in two-factor authentication workflows. Google Authenticator is exactly that, as you pointed out.
- monocasa 8y agoGoogle authenticator generates those hashes from a plaintext key stored on device in a SQLite database. If you can read /data, then you can generate any hashes that Google Authenticator can.
- deleted 8y ago[deleted]
- blitmap 8y agoAnother neat solution: https://krypt.co/ https://krypt.co/
- pat2man 8y agoOr if you have a Touch Bar MacBook: https://github.com/ntrippar/sekey https://github.com/ntrippar/sekey
- maltalex 8y agoIt is neat, but only for SSH. Plus, they're a new company I never heard of. Why would I trust them with my SSH keys?
- Operyl 8y agoIirc their clients are all opensource, go audit the source code and build your own binaries.
- buddylw 8y agoI've been playing with this, and it's mostly good. It solves the key forwarding problem in nested Linux VMs (-A forwarding is kind of bad). I do find it a bit silly that they don't support any iOS or android ssh clients, so they only way to authenticate ssh from an iphone is to connect to a VM first where the linux client is installed.
- jlgaddis 8y agoYes, AgentForwarding is a bad idea... but thanks to ProxyCommand (and now the simpler) ProxyJump, I haven't needed to use it in years.
- Spivak 8y agoFor the purposes of 2FA, your physical machine typically doesn't count as 'something you have' and your phone is really no different.
- amelius 8y agoWhy not? The iPhone is a personal computer (PC) after all, ironic as it may sound.
- _asummers 8y agoYour iPhone is a second factor to all devices except itself.
- zaroth 8y agoRegardless of what screen you are authenticating on, a key stored on the iPhone secure element can always be considered to be a factor in the authentication process. If are logging into a site on your mobile device, and part of the authentication verifies your password and another part verifies that you are in fact on your mobile (e.g. verifying a signature of a private key stored on the device) I would still call that multi-factor authentication. Optionally, there may be a user prompt on the device before allowing the signature. Optionally, the user prompt could also require a local biometric authentication (3rd factor). Or there could be no prompt at all — just a automatic handshake proving it is the same device being used that was originally enrolled. In any case you are constraining the authentication process to only work with access to a specific private key, hence a second factor.
- zaroth 8y agoIf I install a TOTP generator on a machine and setup 2FA on a 3rd party service, and I then later login with a password and a 6 digit TOTP code, that is definitely 2FA. You can argue my TOTP shared secret may or may not be secure enough from malware. But it’s definitely 2FA and it successfully protects against the attack vectors that adding a “something you have” factor is designed to protect against. Better than SMS codes, for sure. Could the TOTP shared secret be stolen if it’s kept in a file on my desktop? Of course! But that fundamentally changes the attack vector from the typical password spraying attack because now an attacker needs to directly target me and compromise my machine. If the TOTP shared secret is in the iPhone secure element and protected by the iOS sandbox, no consumer application could reasonably ask for anything better than that. That’s $1B of security R&D on your side. Another way to think about it is that on-device TOTP is “something you have” just like a saved password is something you have.
- pat2man 8y agoThe only issue with this sort of setup is when you lose your phone and need to set up a new device. Or if you for some reason need to authenticate to a non-personal device. Smart cards have traditionally been used in this way but they haven't really been updated for the mobile world. I could see using a yubikey stored securely in your house for just this reason and relying on the secure element in your phone for everything else. If course if you have two phones, or a computer with a secure element (like the new MacBook Pro) you could just use your other device to authenticate.
- jotux 8y ago>I trust the secure element on the iPhone a lot more than I trust the hardware on the Yubikey. Why?
- pilif 8y agoI don't know about the OP, but for me the reason is that it's made by a company with a much bigger profile than yubico This means that it's under much higher scrutiny by the public. Due to that big profile I also expect security issues to be fixed quickly as Apple has much more reputation (and money) to lose than Yubico. Finding exploits in the iPhone's secure element gains you much more fame than finding exploits in the Yubikey. And finally, Apple has come out very publicly against aiding law enforcement and has a much bigger war chest to fight requests by law enforcement. Yubico has neither.
- sweden 8y agoBut an Yubikey is a passive and isolated device: it doesn't turn itself on, it doesn't run any apps, it doesn't connect to the internet. And if it gets compromised (stolen or exploited), it's cheap enough to throw it away and to replace it with a new and improved version without any hassle.
- zaroth 8y agoStealing a Yubikey gives you immediate access to the 2nd factor, and I might not notice right away. Stealing my iPhone gives you almost zero chance of accessing the second factor, I would notice a lot quicker, and I could revoke access (remote wipe) with a single click versus having to re-enroll a new 2FA at every single site individually.
- YR372zm87 8y agoYou can password protect the Yubikey. That's how mine is setup. Adds an extra step, but I don't worry about losing it.
- zaroth 8y ago
- maltalex 8y agoYou're thinking about authenticating your desktop, but what about authenticating the phone? The phone itself has access to a bunch of sensitive information, and is probably much more likely to get stolen or go in for repair. Perhaps the yubikey can serve as "something I have" to supplement the iphone's pin code.
- tenken 8y agoYour phone that is visible and accessible to every WiFi network is not what I would consider a secure device. A small smart dongle on the other hand, an island unto itself, I do consider more secure.
- matheusmoreira 8y agoDoes the iPhone's secure element implement smart card functionality? Does it allow generating and storing PGP keys in secure tamper-resistant memory?
- amluto 8y agoYubikey OTP is much weaker than a good challenge-response protocol like U2F. I assume that Yubico is supporting OTP because iOS only exposes NDEF data, and NDEF is effectively a one-way protocol.
- kevin_b_er 8y agoAllowing two way communication would permit innovation in connecting devices that are not subject to Apple's direct control.
- deleted 8y ago[deleted]
- crankylinuxuser 8y agoOk, this is dumb. Real dumb. I would trust (the leaked) secure enclave OS than Yubico's offerings. And the Secure Enclave is already built in, versus this 3rd party hardware. Also, using something like andOTP is perfectly fine to run, which is also a U2F TOTP solution. It integrates perfectly with LinOTP, Google Authenticatior, or other 2fa solutions. In essence, if you're using Linux anywhere, 2fa is free to implement, free to manage serverside, and just works. There's no reason for Yubi-anything. Also, within the next few weeks/months, NIST will be stating that phone calls, Texts, and emails are no longer an acceptable 2fa for secure stuff.
- acdha 8y ago> Also, using something like andOTP is perfectly fine to run, which is also a U2F TOTP solution. It integrates perfectly with LinOTP, Google Authenticatior, or other 2fa solutions. It also has a massive attack surface since you need to secure an Android device. The big win for a dedicated hardware token is that there's so little to attack, along with lesser things like not running out of battery at inconvenient moments.
- m-p-3 8y agoI kinda hope they'll make a newer version of the Yubikey that supports NFC and PGP keys bigger than 2048 bits.
- acdha 8y agoAgreed on NFC but they support 4096 bit RSA in the current generation hardware: https://www.yubico.com/product/yubikey-4-series/#tab-specs https://www.yubico.com/product/yubikey-4-series/#tab-specs It suffers the usual PGP-world usability problems so I ended up not using it very much but it was definitely working and takes noticeably longer to generate the key than a 2048-bit key does.
- blklifematters 8y agoNothing to hooray with apples scrappy swift or objc development. Mostly no documentarion, sanboxy and reeeaally slow customer service. Did I mention overpriced also.
- azinman2 8y agoI’d like to see Safari support... does anyone know if it’ll have it (perhaps thru a sharing extension?)
- cwkoss 8y agoI wonder if there is a method to detect NFC at a greater distance than you can read it - could be used to 'find any yubikeys hidden in office desks'