15 ms·
Support for U2F security keys
- afturner 7y agoFinally! Been waiting for this
- zymhan 7y agoIt appears via the screenshot that you can have multiple 2FA devices, which is great. I love my Yubikey in theory, but in practice I'm only using it for services where I can have a TOTP or SMS 2FA backup method, because I'm not convinced it will always work or be available. Even if having SMS 2FA enabled negates any security benefits of the Yubikey. Thus far it's just Dropbox and Gitlab that I use it for, since they're among the few services that allow multiple 2FA methods to be used at the same time.
- the_svd_doctor 7y agoI believe SMS 2FA does not _completely_ negates it, in the sense that if you use your Yubikey all the time (except when you lose it) you still get for instance all the phising protection. Of couse if someone targets you directly, then yes, you lose most of the advantages since SMS 2FA is pretty easy to break.
- nevir 7y agoWhich services that support U2F do not support multiple devices (that you care about)?
- ben1040 7y agoLast I checked, Twitter supports U2F, but only allows enrolling one key. edit: I guess the thread is referring to multiple fallbacks that aren't U2F, but even still, if you're relying solely on U2F it's good practice to have more than one key lest you lose it and get locked out.
- Xylakant 7y agoAmazon/AWS only allows a single MFA device.
- zymhan 7y agoI haven't kept a running list, but just checking a few services I use at work, and Terraform Enterprise doesn't appear to support more than one 2FA method being enabled at a time.
- dickeytk 7y agoI have 3 yubikeys to avoid this problem
- GoMonad 7y agoHow do you manage keeping all the keys "synced" in terms of which services they are registered with. I keep keys in separate locations for safety, but that makes adding all keys to a new account a big pain. This hasn't been a big problem yet because there are so few services that support the keys, but I wonder how people would manage it if it became widespread.
- dickeytk 7y agoIt's a pain, I don't have a good answer. What I'm going to do personally is only use U2F on my most secure services (email, 1Password itself, GitHub). 1Password with the TOTP stored inside of it should be good enough for the others.
- GoMonad 7y agoI like this hierarchical approach. Thanks.
- ralphm 7y agoFor U2F there's nothing to be in sync: each key is added individually, and you don't have to add all of them at once. I.e. if you register the key on your keychain at work, you could later add the backup key in your home vault. For storing TOTP keys on your YubiKeys, those must be the same, so you probably have to add them at the same time, or take a picture of the QR-code before you complete the registration.
- xur17 7y ago> For U2F there's nothing to be in sync: each key is added individually, and you don't have to add all of them at once. I.e. if you register the key on your keychain at work, you could later add the backup key in your home vault. The challenge is remembering to enroll using your backup device. Also, ideally your 2 devices would never be in the same room as each other, otherwise you are at risk of something like a fire destroying both.
- AGKyle 7y agoCorrect, you can add several devices. You can have TOTP + U2F devices or just U2F devices or just TOTP. It's as simple as clicking the button to add another, and walking through the steps. Just be sure to name them in such a way that you can tell them apart. I typically use the identifier on the key itself. It's usually printed somewhere opposite the USB contacts. Kyle 1Password
- graton 7y agoAll the services that I have used with U2F support have supported multiple keys. Google, Gitlab, Github, and some others which I forget. They have all worked with Yubico U2F keys and with the Google Titan keys. Pretty convenient way to have two factor authentication. I like the Yubikey 5 Nano as you can leave it plugged into a port in your laptop all the time.
- swhitt 7y agoAll services except for AWS.
- xur17 7y ago> All the services that I have used with U2F support have supported multiple keys. Google, Gitlab, Github, and some others which I forget. I've run into a number of services that only allow a single U2F key (it's been a while, so I don't remember the exact ones). Even if they do support multiple U2F keys, how do you handle enrolling both? I keep my backup key offsite, so ideally I could enroll it without physically possessing the device. If I have both in my possession at all times (or even sometimes), I'm at risk of losing both of them.
- chimeracoder 7y ago> All the services that I have used with U2F support have supported multiple keys. Google, Gitlab, Github, and some others which I forget. AWS and Twitter are two services which only allow a single U2F device.
- hamburglar 7y agoThis looks awesome and I wish I could use it. Could you guys also consider bringing back the completely-offline mode that doesn't make my password manager depend on a 3rd party service? I'm prohibited by company policy from using my favorite password manager because of this.
- AGKyle 7y agoYou mean the licensed version? It never went away. When you launch you'll be prompted to purchase. On the screens near the bottom there is a line of text about purchasing a license, go that route instead of signing up for the 1Password.com service. Kyle 1Password
- hamburglar 7y agoInteresting. If this is the case, I think you have a communications problem. I was under the impression that after 6.0, the only way to get a license was to have your older one grandfathered. I can't find any information about this on your website. All of the options on your product info pages other than "enterprise (email us for a quote)" show monthly subscriptions only. Where can I see product info about the licensed version? Can you provide a link?
- signal11 7y agoI agree their website is somewhat confusing, it nudges quite strongly towards purchasing a 1Password subscription. However these pages[1,2] makes quite clear that you can purchase a standalone license even if you're not upgrading: > Or, to purchase a standalone license, click “Need a license? We have those too.” After purchasing your license, add it to 1Password. > Or, to purchase a standalone license, click “Need a license? We have those too.” [1] https://support.1password.com/upgrade-windows/ https://support.1password.com/upgrade-windows/ [2] https://support.1password.com/upgrade-mac/ https://support.1password.com/upgrade-mac/
- hamburglar 7y ago
- dexterdog 7y agoHasn't this been in Bitwarden and Lastpass for a while now?
- josefresco 7y agoGot a free YubiKey from Wired. Then I read that mobile is a pain, and that I really need two ... it's sat in my bag now for months, unused. I already use 2FA, and it works good enough - I'm not sold on how this will make my life better, especially on mobile.
- tptacek 7y agoThe primary purpose of U2F/WebAuthn is to break phishing attacks. Code-based TOTP 2FA, the kind you're probably using now, is already adequate to the task of making sure you're not credential-stuffed.
- tpetry 7y agoAutofill of a password manager is a working countermeasure against phishing too: If autofill does not work there is something wrong and you should look closer...
- kevin_nisbet 7y agoI tend to be a little hesitant to use the browser plugins that do autofill, I think most major vendors have had a vulnerability of some sort at some point. Doesn't mean it's unsafe, it's just the tradeoff I prefer is that I'm more likely to be phished on a single account, but less likely to have my entire DB compromised through a plugin compromise.
- pfg 7y agoI can't find a source, but my recollection is that Google developed U2F because autofill didn't work reliably enough, so many users would just paste the password manually anyway.
- tialaramex 7y agoIt doesn't matter whether the technology "works reliably enough" it matters whether the _user_ reliably won't sidestep security by pasting their password in to the phishing site. And that's something we knew the answer to decades ago: No. Humans are bad at giving up. If there seems to be a way forward for the original plan they will press on, regardless of all indications that this now a bad idea. In fact Google had a security override in Chrome for years that was literally typing the sequence "badidea" in recognition of this. It's not specific to computer security, it happens in incident management, there's a seminal example from years back where a train breaks down, and the incident manager sees that step 1 of the response is to send a recovery train to the location, and literally _hours_ later, with passengers stranded and desperate - that manager was still wrestling with how to get the recovery train to the location so they could proceed to step 2, rather than realising that problems with the recovery train meant they needed to _abandon the entire plan and re-assess_ because humans are not good at that.
- javagram 7y agoI have never used 1password.com. Adding 2FA to it is great but I think the best security is likely still just to sync and use local apps for this data, to avoid being exposed to any JavaScript vulnerabilities or if 1password.com were ever hacked.
- alienreborn 7y ago1Password has Wifi Sync option too.
- javagram 7y agoYep! 1password is great. I do use their cloud sync service with all the apps, I just don’t ever use the website or the browser extensions to limit my exposure.
- AGKyle 7y agoNote that the browser extension actually does limit your exposure quite a bit. You make trade offs here. For instance, if you aren't using the browser extensions, how are you getting your password to the browser to sign in? Copying and pasting? It's possible for any app on your system to read the clipboard. Drag and drop should be a better alternative there, as we now support that in 1Password 7. The extension though uses either Safari App Extension (for Safari, obviously) or Native Messaging Host (Firefox and Chrome browsers) and aren't susceptible to clipboard type snooping. The browser extensions also only present items that match the website you're on. This helps a lot in phishing attempts. So, yea, you could not use the browser extensions but you're going to have to trust that YOU always do the right thing. Note again that 1Password does not "auto fill" like other password managers, where simply visiting the site fills the data in. You always have to explicitly ask 1Password to fill into the page. Just some insight anyway. Kyle 1Password
- javagram 7y agoThanks Kyle. I do appreciate your response! And the tip about drag-and-drop, I may make use of that :)
- currymj 7y agoI have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?
- kitten_smuggler 7y agoA bluetooth capable U2F device like the Titan.
- dickeytk 7y agoyou can't use that with computers. You have to use a dongle + cable to connect to new macbook pros
- anonuser123456 7y agoI use it on my laptop daily.
- kevin_nisbet 7y agohttps://solokeys.com https://solokeys.com are an option as well if you like open hardware. https://github.com/solokeys/solo https://github.com/solokeys/solo I think the NFC ones are shipping after they worked out some kinks.
- 7y ago
- toastal 7y agoI've had an OnlyKey for a couple of years now. It offer 12 slots per profile and 2 profiles, and the slots supporting TOTP, U2F, Yubikey, plaintext and a whole lot of other tools. With the configuration app and firmware open source, I'm really surprised I've never seen anyone else with one.
- HungSu 7y agohttps://onlykey.io/ https://onlykey.io/ I assume you mean this - it looks great!
- euroclydon 7y agoSo this works with 1Password the website? I've been using 1Password for years, and never go to the website? How does this make my life better? Can I unlock 1Password the desktop app with the U2F key?
- iscrewyou 7y ago> So while it works great as your second factor in those browsers, for now you’ll still need an authenticator app set up to use with the 1Password desktop and mobile apps (and any unsupported browsers).
- AGKyle 7y agoOur implementation of 2FA only happens when adding your account to a new device. Subsequent unlocks do not require any sort of 2FA except for certain conditions. Our apps do not currently support U2F/WebAuthn when signing in, so they'll default back to TOTP based until we implement support for U2F. We aren't making any promises as to when this will arrive but at least two of our apps now have some form of support for it internally. It's far from complete and not ready for users but it is being worked on. Note that U2F in this case is only about authentication, not decryption of data. This is why it's only used on initial setup of your account on a new device. The cryptography side for unlocking 1Password is entirely independent of U2F/MFA. Hope that helps but let me know if you have any questions. Kyle 1Password
- evo_9 7y agoI switched recently to Bitwarden. 1Passwords pricing/subscription changes was the the push I needed. Bitwarden has been fantastic, I highly recommend it. https://bitwarden.com https://bitwarden.com
- judge2020 7y agoSame, but decided not to use the TOTP feature so that the password manager isn't a single point of failure.
- sorum 7y ago$2.99 per month is too steep of a price to pay for your personal security? Really? I'd dump my Spotify/Apple Music/Netflix/whatever in a heartbeat, if I had to choose between paid subscriptions in my life
- Fnoord 7y ago$3 per month can be a lot of money, depending on where you live and your financial situation. Bitwarden is free as in a beer and free as in speech. Only if you want the 2FA features you need a subscription. Then Bitwarden costs 10 USD per year. That's approx as much as 1Password asks for 3 months. Ie. Bitwarden is almost 4 times as cheap. For that price you get a very good program with an open source frontend, and an open source backend (third party, in Ruby). And Lastpass, after they were acquired by LogMeIn, has the balls to go from 12 USD/year to 24 USD/year. Without any additional features whatsoever a 100% price increase? That's why I went shopping. And I ended up at Bitwarden.
- icebraining 7y agoI'm selling water bottles at $100/gallon. Considering water is literally essential to life, how many can I get you?
- sorum 7y agoYou must have had better ones than _that_, when you were thinking up a witty reply. I hope that wasn't you bringing your best.
- bloopernova 7y agoI'm seeing several links to different physical keys in the comments. Is there somewhere/someone that verifies these keys? Like a 3rd party testing/standards body? I've always had it drilled into me that doing crypto yourself is fraught with peril. It seems that doing hardware would be doubly dangerous. I'd want more verification that the implementation is correct and "strong".
- klodolph 7y agoI think verification that the implementation is correct is easy enough, which implies that it is "strong", because these devices simply implement a spec. What you might want to look at is things like hardware hardening or side channels. (Whether or not you consider this a matter of "correctness" can be argued, but here I would consider correct = implements correct algorithm.) I think attacks against U2F devices are fairly difficult because you can't really use them as any kind of oracle, just due to the way the user interface works. But I am not a crypto expert, I just know how U2F works.
- dkanejs 7y agoThere are FIPS versions of Yubi Keys: https://www.yubico.com/products/yubikey-fips/ https://www.yubico.com/products/yubikey-fips/ These are validated by NIST (National Institute of Standards): https://csrc.nist.gov/Projects/Cryptographic-Module-Validation-Program/Certificate/3204 https://csrc.nist.gov/Projects/Cryptographic-Module-Validati...
- ecesena 7y agohttps://fidoalliance.org/ https://fidoalliance.org/ Note that most keys are level-1 certified, i.e. against online attacks. Physical attacks are generally not much important, because if an attacker has access to your key, he can simply use it. (unless you went through the additional hassle to set a pin, but very few people do it.)
- mevile 7y agoIf this is the sort of thing where I can just tell 1password this device is OK with 2 factor, once per device, I could use this. If this the sort of thing that whenever I wanted to lookup a password, forget it. Even if I had to two it once a week or once a month I wouldn't bother. Maybe if I were paranoid about being a target I would, but I'm not.
- wereHamster 7y agoLiterally the first paragraph: > Last year we added two-factor authentication to provide another layer of protection for your 1Password account. When this is enabled, you are prompted to enter your second factor any time you sign in from a new device. If you read it carefully, you'll have the answer to your question.
- charlietango92 7y agoonly tangential, but I've wanted to carry my Yubikey on my keyring, but have always been nervous about making it unreadable by sullying the contacts. Should I be concerned about this? Where do you all carry them?
- equalunique 7y agoI carry mine on my key ring. No issues since I bought it around 3 years ago.
- hdabrows 7y agoThat's how I've been carrying mine for the last four years and it's fine. I think you're more likely to lose it than to damage it. I have a second one that's identical (registered to the same services) that I keep in a safe place.
- the_svd_doctor 7y agoI've had a "blue" Yubikey (the one around 20$) on my keyring for 2.5 years. Still works like a charm. Very robust stuff.
- remus 7y agoI've had mine on a keyring for 6 months and it hasn't shown any signs of wear. I'd be surprised if it doesn't last at least another 18 months.
- btrettel 7y agoAfter about 6 months of use, my blue Yubikey is tarnished but functions as intended.
- wiredfool 7y agoI’ve hade one for 10 years or more and it’s fine. It’s a durable little thing.
- jbergknoff 7y agoI came across https://www.thingiverse.com/thing:2588513 https://www.thingiverse.com/thing:2588513 in some Reddit thread about this, got it printed on my public library's 3d printer, and it's been pretty nice. (Had to etch some grooves in the sides of the Yubikey so there's something to grab it to pull it out of the sheath, but that wasn't a big deal)
- hsk823 7y agoYAS!
- technofiend 7y agoJust thought I'd mention that PayPal recently quietly added TOTP second factor support. It's not u2f but it's better than SMS. Perhaps u2f is in the cards now since they're listening to customer feedback on the issue.
- shay_ker 7y agoCan you use Yubikey NFC to do 2FA on most/all iOS apps? That's my biggest barrier to getting a Yubikey.
- jehteh 7y agoSwitched from lastpass to gnu pass and storing my private subkeys on a couple of yubikeys has actually worked really well for me (took a few days to get my head around gpg and smartcard setup, but that was worth doing even if I didn't setup pass). That said, I am running android, windows/WSL and ubuntu; other platforms may not be so painless.
- xaduha 7y agoI'm using this with a contactless smartcard, works just fine on Android https://github.com/tsenger/CCU2F https://github.com/tsenger/CCU2F
- vmurthy 7y agoFor those of you who have the desktop version - it looks like U2F support is a work in progress: "So while it works great as your second factor in those browsers, for now you’ll still need an authenticator app set up to use with the 1Password desktop and mobile apps (and any unsupported browsers)"
- sleepybrett 7y agoSo this only applies to 1password.com not the desktop app synced through cloudprovider/filetransfer/whatnot?