9 ms·
GitHub Supports Web Authentication (WebAuthn) for Security Keys
- patrickmcnamara 7y agoGreat. This means I can log in on my phone again.
- munchbunny 7y agoIn the thread from the Yubico announcement earlier this week, someone brought up the question about why you can't disable SMS for recovery codes (SMS recovery codes, not SMS 2nd factor), since that undermines the security benefit of having your 2nd factor moved entirely to FIDO or OTP. Are there plans to fix that?
- akerl_ 7y agoTo clarify: you can disable SMS MFA on Github (or never set it up in the first place). Doing so does require setting up TOTP, though you’re able to validate the initial code and then delete your copy of the secret key.
- munchbunny 7y agoSorry, I maybe wasn't clear enough. You can disable SMS MFA (I did), but it didn't sound like you could disable SMS recovery codes, which is the other section further down in the UI for configuring your login setup.
- akerl_ 7y agoAh. Those are disable-able as well: https://imgur.com/a/bLnRuOq https://imgur.com/a/bLnRuOq
- munchbunny 7y agoAwesome! I'm glad I stand corrected.
- bamboozled 7y agoBe careful doing this, I’ve had friends who lost their accounts and it was a pretty big loss for them.
- roca 7y agoMake sure to print out some backup codes. Also I have two Yubikeys authorized for each of my U2F/Webauthn accounts. Fortunately managing multiple hardware keys is much easier with U2F/Webauthn than with TOTP... at least with Google/AWS/Github, you can add a new key at any time, while with TOTP I had to generate a new TOTP secret and update both keys at the same time.
- marksomnian 7y agoYeah, that seems like the best bet - either hardware key or TOTP (because, although hardware keys are better for security, not all users will have one - cf. myself), and then store your backup codes in a password manager.
- michaelmior 7y agoI would assume that GitHub support would be willing to provide some out of band authentication to allow someone to recover an account if all other options had been exhausted.
- Klathmon 7y agoI personally hope they dont. Time and time again it's been shown that one of the weakest links for account security is customer support. It's pretty trivial to gather enough information to impersonate someone well enough for most support reps to believe it's actually you. It's also part of the reason why SMS is so insecure, because legally most phone companies can't not allow you to transfer your number, and the ways they can verify you are you is limited. If they do allow support account recovery, I hope they allow the ability to disable it for those who don't want the extra attack vectors.
- jeromegv 7y ago
- sebazzz 7y ago> GitHub supported physical security keys using the experimental U2F API for Chrome Yes, and to make it worse, they used user agent sniffing instead of feature detection even though it work fine in Firefox. Firefox enabled U2F because many sites which do implement U2F, do not implement WebAuthn yet. Luckily, it appears Github is now on the right track.
- icelancer 7y ago>> Yes, and to make it worse, they used user agent sniffing instead of feature detection even though it work fine in Firefox. My bank and my retirement accounts do this too. It's infuriating. I switched to Firefox recently due to failures in Chrome Sync and now I get this as a reward. Wonderful.
- sebazzz 7y agoLuckily Firefox features per-domain overriding of the use agent: general.useragent.override.[domain]
- rehemiau 7y agoCurrently using this on Firefox for Android through an extension, works great: https://addons.mozilla.org/en-US/firefox/addon/uaswitcher/ https://addons.mozilla.org/en-US/firefox/addon/uaswitcher/
- icelancer 7y agoJust tried this with my Yubikey Nano and Vanguard Investments, after changing my u2f to "true" in about:config. Does not work at all. Vanguard shows the Yubikey login prompt but it doesn't activate the Yubikey, and pushing the key just spits out a OTP and dumps it to the browser search bar. Oh well.
- richipargo 7y agoI used to have this issue but in my case it just meant I was missing some OS dependencies so it might vary on a case by case
- StavrosK 7y agoThis is fantastic. I look forward to finally having much easier authentication on the web. Imagine browsers syncing between devices a single encryption key that will authenticate you to all sites, which you can easily back up to a piece of paper. EDIT: Unfortunately, it looks like the WebAuthn credential is only used as the second factor, so you can't use it to replace your password yet, let alone your username.
- CrendKing 7y agoAs discussed before, biometric data (used by WebAuthn) will never be used as the single factor for authentication, due to the fact that you can't revoke your face or fingerprint once that data is hacked or leaked. Also, single encryption key is risky (in the way as using the same password across all websites) as it could be hacked or leaked. Username/Password would still stay as the primary authentication method at least for near future IMO.
- StavrosK 7y ago> biometric data (used by WebAuthn) will never be used as the single factor for authentication WebAuthn doesn't use biometric data, the authenticator does. You can just as easily use a PIN or whatever you want. > Also, single encryption key is risky (in the way as using the same password across all websites) as it could be hacked or leaked The difference is that one compromised site can't leak your encryption key, someone would have to physically get it from your computer or steal your security key (and, probably, need to guess the PIN in three tries).
- dane-pgp 7y ago> WebAuthn doesn't use biometric data, the authenticator does. You can just as easily use a PIN or whatever you want. Except the standard permits sites to only trust authenticators with specific features, or rather from a specific whitelist of manufacturers/models: https://www.imperialviolet.org/2019/01/01/zkattestation.html https://www.imperialviolet.org/2019/01/01/zkattestation.html Of course, not every site will make use of this DRM-like anti-feature, but I can well imagine that a lot of sites/industries will adopt policies that treat non-biometric authenticators as insecure.
- SEJeff 7y agoAnd multiple security keys at that! This is excellent.
- kmfrk 7y agoI've been waiting a million years for another branded sale on YubiKeys like the last time GitHub did one. Those things are so expensive. Seems like a cool thing to sponsor, too - as long as it's tied to accounts to prevent underhanded measures.
- ericseppanen 7y agoA Solo key is $20. https://solokeys.com/ https://solokeys.com/
- CameronNemo 7y agoNote that the feature set on this is limited. Specifically it is missing GPG (and thus SSH) support. It may be added via a software update if the somu campaign goes very well. But frankly that is a long shot. https://www.crowdsupply.com/solokeys/somu https://www.crowdsupply.com/solokeys/somu Of course if you only need WebAuthn then solo keys are a great option.
- petershinners 7y agoI noticed ArsTechnica is providing a free Yubikey with subscription to their "Pro++" yearly subscription ($50/year). This also provides a 20% discount on additional dongles. https://arstechnica.com/store/product/subscriptions/ https://arstechnica.com/store/product/subscriptions/ This may not be the "deal" you were looking for. But if you were considering a subscription anyways you could already be a winner.
- vel0city 7y agoThe $20 Yubico Security Key supports WebAuthn and FIDO2. The NFC-enabled unit is $27. https://www.yubico.com/product/security-key-by-yubico https://www.yubico.com/product/security-key-by-yubico
- u801e 7y agoI wonder if Github has ever considered allowing a 2FA via the use of the private ssh key that's used for running git push or git fetch/pull?
- tialaramex 7y agoFiguring out what sets of unrelated operations it's safe to do with the same private key is a problem. Definitely don't do this without a cryptographer examining all the operations done and telling you it's safe. Generally if asked they'll tell you to just make a new key instead because that's definitely fine. Example: If an archaic backup MX mail server with private RSA key P is allowing SSLv3 "for backwards compatibility" then bad guys can use that to impersonate an otherwise unrelated TLS 1.3 web server that shares private RSA key P.
- tptacek 7y agoIn a somewhat related vein: it would be really fantastic if Github allowed the same SSH key (in my case: a Yubikey-resident SSH key) on multiple accounts; we use separate accounts for different clients, and Github's refusal to allow an SSH key to be used on multiple accounts means I can't use Yubikey SSH keys for those. I get that this is a niche-y concern. :)
- deleted 7y ago[deleted]
- chrismorgan 7y agoThat would require the ability to specify the username somehow, would it not, e.g. using tptacek@github.com:… and example@github.com:… instead of git@github.com:…?
- CameronNemo 7y agoYeah something tells me this is a deep change related to how they manage identity. GitLab has the same issue.
- DangitBobby 7y agoBitbucket allows you to use your SSH key on as many projects as you like, IIRC. I actually really like Bitbucket as a platform, I wish more people would use it.
- andrewshadura 7y agoThey were a great platform, but they aren't any longer.
- DangitBobby 7y agoGo on...
- mbesto 7y ago
- joshca 7y ago> But there’s more—GitHub’s move toward WebAuthn makes it possible to use your laptop or phone as a security key without carrying a separate physical key. How does this work? Is an OTP generated on phone with Google Authenticator like app and that OTP needs to be punched into the login form?
- TheChaplain 7y agoAlso would like to know how this works for multiple accounts...
- dwaite 7y agoWeb Authentication is basically generating and proving ownership of a private key. You have some hardware/software that manages these keys - it will generate a key at registration time, and then prove ownership as part of authentication. The keys are tied to a web domain and the domain is also included on the challenge/response, which breaks active phishing attempts. When you are using WebAuthn as a second factor with a hardware key, you are typically using non-resident keys. These are keys that aren't being stored by the authenticator, only by the relying party (in this case GitHub). A "handle" is given at registration, which must be re-supplied at authentication. This is actually how the U2F keys work - the handle has the only copy of the exported, encrypted keys or key material, so the authenticator can't understand a request for authentication without getting that handle. So, in this case even though it is the same physical hardware authenticator, you have done two registrations, which have generated two separate generated key pair, each with a key handle. Those key handles are saved to different accounts. When I use the authenticator as a second factor, only key handles associated with that account are used for the authentication challenge. There are wrinkles here because of the diverse ecosystem, of course. Some software implementations (like Windows Hello) have no premium on storage, so they will still store second factor keys. These still need to behave as above, but Windows will technically know it has been used multiple times on the same site. Also, when using Web Authentication for primary authentication, you use what is called a resident key. In this case, the key is saved in memory along with metadata on which site it was generated for. The challenge doesn't include handles, but is effectively asking "do you have anything perhaps for GitHub.com?". In this case, some authenticators simply won't support multiple accounts. Others will, and the browser or operating system will take responsibility for selecting which key is shared, via native UI.
- user6789675 7y agoI think security when it comes to third-party products is relative to personal value one sees into that product and to personal use case. If your GitHub account is really that important as to use your fingerprint each time you access it, sure it is nice GitHub can support that. But if you do not really mind and are happy with a password, that maybe unlike your finger, you can share with someone in other side of world if you really like to, then why not use a password. I would expect GitHub should not prevent that. It is sad to see a trend to really "make sure it is you" started by Facebook and Google taking over in all mainstream online services and it is even worse, to have people believe it is the only good for them.