5 ms·
Is there any inexpensive USB-based security keys? I'd love to get one for my Mac and PC but Yubico Nano is $50; I would like two of these, but they are $100 al
by otterpro 8y ago
Is there any inexpensive USB-based security keys? I'd love to get one for my Mac and PC but Yubico Nano is $50; I would like two of these, but they are $100 already.
EDIT: I also see Yubico Fido Keys which are $20 each (and $36 for 2). Are there any differences between these and the regular Yubico keys?
- resonanttoe 8y agoI looked in to it a while ago, but none except for portability. The Nano's are designed to take up a USB slot and be semi-permanent in there. That is, they can be removed, but its not as easy as removing a normal USB key. Either good grip or a pair of pliers for the fingernail-less.
- JCharante 8y agoAnd you have to be very delicate when using tools on it or else you'll chip away at it. I've found needle and thread to be effective.
- resonanttoe 8y agoyeh this is probably miles better than what I do to my Nanos.
- klodolph 8y agoYubico Fido keys (Security Key by Yubico, the blue ones) only support FIDO U2F. This lets you use them for logging into GMail, DropBox, and other websites which support FIDO U2F. You can't store passwords or other data on them. This means you can't use them for storing SSH keys or things like that. There's not some technical reason why you can't use FIDO U2F for SSH authentication, it's just that the software support isn't there yet. You could probably hack this together yourself, the idea would be that you generate a SSH key on your computer, authenticate to some certificate manager with U2F, and then use that to install the public key on the computers you want to access. You could then have it automatically expire 8h later, forcing you to reauthenticate, giving attackers a shorter window to compromise your machine if they want to hop to others with SSH.
- jrockway 8y agoThe $20 Yubikeys only do U2F; the more expensive Yubikeys also have the ability to generate one-time passwords and act as smartcards (for things like signing git commits). I have the Nanos in all my computers because I'm used to that setup from working at Google, but that's more expensive than what I actually need.
- tptacek 8y agoIf you have to ask, get the super cheap ones; you probably aren't going to use any of the features on the expensive ones (like the nanos and the Y4s). You will read lots of people talking about the cool things they do with their Y4s, but really they're just doing it because they can, not because there's a well-thought-out security benefit they're getting (I'm as guilty of this as anyone). 95% of the benefit of a security key is simply U2F.
- ehsankia 8y agoI don't think it's so much about features, but I do think there's a huge difference between having a nano and a normal sized one, especially on a laptop. Being able to leave it in instead of having to take it out of your wallet and plug it in every time makes a big difference in usability, which in turn makes it much more likely that you'll want to use it everywhere.
- tptacek 8y agoIt's funny because I see it the opposite way: the problem with the nano is you'll want to leave it in all the time, which reduces your practical security. I go out of my way to keep the security key on my physical keychain; I don't even like leaving it in my bag, where it might get stolen along with the computer.
- joshuamorton 8y agoWhat's the threat model this protects against? (In other words, what's better about having the security key being on your keychain vs. be a permanent part of your computer)
- tptacek 8y agoI am less likely to lose both at the same time as I am to lose just one, and you'd need both of them to get access to accounts.
- srathi 8y agoUnfortunately the $20 one is only available with USB-A, not USB-C.
- mimming 8y agoThe U2F-Zero is about $9, and the cheapest U2F device I know of. They work well, but aren’t as durable as other options. https://www.amazon.com/U2F-Zero/dp/B01L9DUPK6 https://www.amazon.com/U2F-Zero/dp/B01L9DUPK6
- Tomte 8y agoI‘d like to add a related question: I already have three or four U2F keys. Is there any reason to upgrade to FIDO2 keys?
- StavrosK 8y agoNot yet. I'm writing a Django library for webauthn support (i.e. logins without usernames or passwords), but no browser supports that yet, that I can see. They only support the second-factor mode, not the first-factor.
- dwaite 8y agoIf you request resident keys the browsers seem to switch over. Chrome Canary had it hidden behind a command-line flag last I checked (a month ago, which is an eternity considering how hard they are pushing)
- ktta 8y agoThe cheapest way to get a yubikey in the US right now is to subscribe to wired for $10 for a year. You get a free YubiKey 4 within a month of your subscribe date.