3 ms·
I look forward for a more robust and durable hardware design. Maybe a ruggerized version?
by pibefision 8y ago
I look forward for a more robust and durable hardware design. Maybe a ruggerized version?
- Operyl 8y agoHave you ever used a YubiKey? Those things are beasts, I’ve yet to destroy one during my use and I am not a careful user.
- georgyo 8y agoI don't know how much more ruggerized you need it. It's already pretty dam strong. I've had a neo on my keys for years and it shows no sign of ware. They already are water proof and can be run over by a car. So unless you want to take a hammer to it, it should be rugged enough.
- chimeracoder 8y ago> I don't know how much more ruggerized you need it. It's already pretty dam strong. I've had a neo on my keys for years and it shows no sign of ware. The first batch of the 4Cs were notoriously fragile. The plastic would break within a few months of normal use.
- georgyo 8y agoI was unaware, but I guess that sorta makes sense. I have only done with USB A style, which is an Epoxied PCB which makes it fairly hard to break. USB C has a connector that cannot just be the PCB, and so it needs a housing and such.
- chimeracoder 8y ago> I was unaware, but I guess that sorta makes sense. I have only done with USB A style, which is an Epoxied PCB which makes it fairly hard to break. USB C has a connector that cannot just be the PCB, and so it needs a housing and such. The Yubikey 4C nano is hardier than the original Yubikey 4Cs were. I've had mine in for months, and it hasn't broken. That said, I should note that my laptop (Macbook Pro) also decided to provide insane amounts of power to the USB-C ports on the left side, which fried the Yubikey - literally, there was smoke - and melted the plastic. (That's definitely Apple's fault, though, not Yubikey's fault).
- mtgx 8y agoI'd be more concerned about general reliability. How long will these last? Because I think they should last at a minimum 10 years. If you only use one for an account, and it breaks on you, you're screwed. So I would use at least 2, but hopefully websites will allow this, and that will probably be the largest bottleneck in the future. I couldn't care less about "SMS backups" or such nonsense, as that completely defeats the point of using a hardware token. Your account will only be as secure as your phone number is.
- zjs 8y agoI configure a second YubiKey as a backup, and disabled SMS-based recovery where possible. Many sites allow this explicitly, and will let you view details about the last time each key was used to log in. Some sites that use TOTP only allow for one "authenticator" to be configured. In those cases, I scan the same QR code into each key. This process requires you to retrieve your backup key from whatever safe place you store it in when configuring 2FA on new accounts, but that feels like a reasonable trade-off; I don't make new accounts very often, and when I do I can wait to configure 2FA until I have access to my backup key.
- emlun 8y agoMy friend lost his YubiKey and found it embedded in his gravel driveway six months later. Still worked like nothing had happened.
- waldfee 8y agoI've had my yubikey 4 nano for a year now. I have it on my keychain and it has weathered much abuse. it has a few scratches but that's about it. it's a very durable thing