3 ms·
What does this offer over Yubi?
by locusm 8y ago
What does this offer over Yubi?
- ekingr 8y agoThe wireless one has Bluetooth - which is the only way to go on iOS for now.
- carc1n0gen 8y agoYou may be interested in some yubikey iOS news that came out in may https://www.yubico.com/2018/05/yubikey-comes-to-iphone-with-mobile-sdk-for-ios-and-lastpass-support/ https://www.yubico.com/2018/05/yubikey-comes-to-iphone-with-...
- ekingr 8y agoYes. Unfortunately it is still only OTP (vulnerable to fishing). Let’s hope that one day Apple opens full access to the NFC chip.
- stephengillie 8y agoHow secure is Bluetooth - how do we know snoopers aren't stealing keys wirelessly?
- mkj 8y agoThe most likely snoopers are far far away, probably even a different timezone. If you have local burglars around they'll just break your windows and doors to get things anyway. (And Bluetooth isn't that bad either?)
- numbsafari 8y agoOr just sit down next to you for a few minutes until you use your device and then walk away? I'd rather force them to smash my windows and doors rather than just give them what they want in passing.
- SkyPuncher 8y agoLet's be real, how often does an attack like that happen? Yes, a localized attack is still possible but you probably have a different set of worries if attacks are going so far as to be within a short distance of you. These tools are about reducing the effectiveness remote attacks which are much more logical to carry out.
- stephengillie 8y agoHow often do you work from a coffee shop? Ever wonder if anyone else in the shop has a minimized wardriver or "blue-driver" sniffing wireless connections? Or maybe their device is infected with a trojan, and a remote attacker is using their device to sniff a random network, which you happen to also be using.
- jwr 8y agoReally? I would assume that the snoopers have access to another Bluetooth-enabled device nearby, such as pretty much any modern desktop or laptop computer.
- AdmiralAsshat 8y agoWouldn't a pilfered TOTP code be useless after five seconds anyway?
- jrockway 8y agoThey tend to last for a minute, but 5 seconds is more than enough time for the phishing site to submit it and have it work. TOTP does not solve phishing in any meaningful way.