9 ms·
Getting Started with Security Keys
- matheusmoreira 7y agoThese hardware tokens usually support PGP as well! It's possible to generate a full set of keys on the device. Combining this with an offline primary key makes for a very secure system that's also relatively easy to use.
- tialaramex 7y agoMost FIDO devices don't do anything else. Yubico sells a lot of products that do, but Yubico's cheapest line of FIDO compliant USB keys, and most competitors cheaper products do not do anything except FIDO.
- dickeytk 7y agoYeah and you really want FIDO. It's such a better experience.
- deleted 7y ago[deleted]
- burner589432 7y agoUnpopular opinion: These keys are about selling the idea that physical-based security is somehow magically better. If you have good password hygene (read: a decent password manager) then I'll need to breach your host to obtain it - if you use a security key, I'll have to breach your host and hijack your session which is slightly more convenient but chances are you're royally screwed once you're breached anyway. Sure there's some edge cases where this might work (one-way keyloggers, etc) but these aren't realistic threats for a large majority of people. Somehow a sales team have taken a bullet hole, and attempted to use a square peg to band-aid it. Stop buying stupid products and just use a damn password manager.
- bodhi 7y agoHow about phishing?
- datguacdoh 7y ago100% this. Phishing is incredibly common, really difficult for even sophisticated users to detect when done well, and the best password manager isn't going to help you. A security key will all but guarantee that this isn't an issue and is a pretty good UX too.
- kadoban 7y agoCorrect me if I'm wrong, but password managers can prevent quite a lot of phishing, because autofill can automatically check the domain. It would be abundantly obvious to me if I were going to put my paypal password into anything but paypal, for instance, because I wouldn't even have the option. I'd have to copy/paste if I wanted to, which would up my suspicion level to the extreme. (this is not to downplay security keys though, I think they're very important)
- pvg 7y agoIt would be abundantly obvious to me That's what people say but even security experts have fallen for phishing attacks. And since the autofill is not 100% reliable, it's not that unusual to go into the password store and manually get the password out of there.
- kadoban 7y agoIt's really quite unusual. I'm not sure what password managers these security experts are using, but there's no way it works like mine (bitwarden). I've never had it fail to recognize the domain, which is good because that seems like really obvious functionality. I have had it fail to autofill due to site implementation, and the couple of times it happened I was extremely on my guard and triple-checked everything before proceeding. I think that's the important part of this, the manager has to be reliable enough that the bypass mechanism stands out _a lot_, and the user has to be aware.
- ggm 7y agoSSH key storage needs more info I think. I am using SSH enough that this '...can also do SSH...' would want to be the main topic. advanced modes disabling API keys means a lot of the older third party integrations which depend on a simple API token are SOL. this worries me, lockin risks.
- ryukafalz 7y ago>SSH key storage needs more info I think. I am using SSH enough that this '...can also do SSH...' would want to be the main topic. Different audiences, I think - this article doesn't go into technical details that often besides mentioning various protocols and what they do. Using a Yubikey for SSH (either via GPG or X.509 certs) is significantly more involved than using one for U2F/FIDO2. There's a pretty in-depth guide here on using one as a GPG smartcard with SSH (that's what I do): https://zeos.ca/post/2018/gpg-yubikey5/ https://zeos.ca/post/2018/gpg-yubikey5/
- allset_ 7y agoFor bonus points, you can also sign your Git commits.
- ryukafalz 7y agoYup! And it's simple enough to do this automatically by just putting this in your gitconfig: [user] signingkey = <your GPG fingerprint here> [commit] gpgsign = true
- Boulth 7y agoYou don't need signingkey if you have a GPG key with the same email as your git user.email (I guess that's the majority of cases).
- cuu508 7y agoThere's also DrDuh's pretty comprehensive guide https://github.com/drduh/YubiKey-Guide https://github.com/drduh/YubiKey-Guide
- ssivark 7y ago> Switch your carrier to Google Fi Now no one can socially engineer access to your account -- including you yourself, in case you're locked out :-)
- 1984victim 7y agoSo is Google Big Brother?
- breadandcrumbel 7y agoOP comment from Reddit post: >Hey folks, OP here. I’ve been using security keys for a few years now and decided to spend some spare time over the last few months writing this up. Despite the name it’s pretty detailed (15k words!) and hope it can help folks understand the benefits of security keys and what fido2 brings to the table.
- arshbot 7y agoThere is a depressing lack of open standards with these off-the-shelf physical tokens. It's unfortunate that a company's security can rely on the APIs of another company which could go bankrupt and disappear at any time.
- couchand 7y agoThis comment held water about five years ago, but times have changed.
- skybrian 7y agoI would put greater emphasis on not locking yourself out, since that's the most likely threat for many people. Losing your phone (or having it die on you) is common and you should assume you'll do it sooner or later. Print out backup codes and store them somewhere safe that you won't forget before enabling two-factor authentication that depends on you having your phone or other device that can break.
- vel0city 7y agoIncluding printable backup codes, most services supporting FIDO U2F or WebAuthn support tying multiple security keys to your account. Many of these authenticator devices are pretty cheap these days, its not insane to have a few of them. Have one on your keychain, another in a desk drawer, etc.
- chowell 7y agoI was super surprised to learn AWS will only allow you to register a single FIDO token - the inherent lockout risk pushed me back to using OTP with the seed stored in multiple Yubikeys.
- blintz 7y agoThis is actually against the WebAuthn spec (https://www.w3.org/TR/webauthn-1/#credential-loss-key-mobility https://www.w3.org/TR/webauthn-1/#credential-loss-key-mobili...). Hope they fix it soon.
- bradstewart 7y agoYea it's very annoying. I ended up making multiple IAM users--one for each of my security keys.
- hsivonen 7y agoIt's bad that many sites require you to set up TOTP (single seed) before they allow you to set up U2F (multiple keys), so you have the problem of having to take care of the TOTP seed anyway even if you have multiple U2F keys. (It's even worse when sites forget the U2F keys when you regenerate the TOTP seed.)
- undefined3840 7y agoFor some reason I‘m basically locked out of any paid Google product because my Google Pay account is disabled for whatever reason. I think it might have been flagged for fraud years ago and now cannot use it at all, including for Fi. It’s crazy.
- londons_explore 7y agoSet up a new account, and remember not to link the new or old accounts by way of a recovery email address or using the same phone number. It's a bit of a hassle, but most things you can transfer over between the accounts, and then just dump the old one. Lots of effort, but the only way unless you know an employee to get the block removed.
- zie 7y agoOr just get off the Google bandwagon. Googles customer service: None Google's care of their users: None Google's desire to sell every single thing about you they can figure out: Unlimited.
- SaturateDK 7y agoTo be fair they may have customer service, but you are not the customer but the product.
- alpb 7y agoI can't help but think the author has recommended (1) storing backup keys (presumably in 1Password?) (2) storing OTP key generation QR codes in 1Password, so it can generate OTP codes for you. Doesn't this defeat the whole purpose of "two"-factor authentication? If your 1Password gets hacked the attacker has both your passcode and one-time password? You should consider keeping these two separate: If your 1Password unlocks with FaceID, do not make your Authy (or etc.) also unlock with FaceID. Otherwise, you're defeating the purpose of 2FA (something you "know" and something you "have"), I think.
- vbezhenar 7y agoSome websites insist on using 2FA, even if you don't want it.
- regecks 7y agoFurther down in the same article: >but you don't really want to have your password manager also store OTPs
- wonnage 7y agoIt's slightly less secure but much more convenient, which I think is worth the trade-off. Just having 2fa on means you don’t have to worry if a website has its passwords compromised, which is probably the biggest threat for most people.
- jen729w 7y agoSee my comments elsewhere in this thread. I’d argue that ‘having unique passwords for every site’ is much more important than 2FA when it comes to the consequences of a site’s database being compromised. For instance, I’ll happily give you my password to ‘My Vodafone’. It’s nXewr7Vq4f)s9>ky. It really is. I don’t give a shit if their database is compromised, it doesn’t affect the rest of my life. (I haven’t been a customer in about a decade. The login no longer works. You get the point.) 2FA adds nothing to this scenario. I should assume that an attacker who has compromised the site’s database has also compromised their OTP systems.
- peterwwillis 7y agoI think calling this 'paranoid' is a bit misleading. Paranoia suggests you are deluded or irrational, and that nobody's out to get you. In reality, people might be out to get you, just like walking a city street, someone might be looking to mug you. The difference is, they aren't looking for you specifically, the chances are pretty low of you running into them, and you shouldn't be overly worried or take too many precautions just because of that possibility. But you should be informed, and let your awareness of the possibility inform your actions.
- sebazzz 7y agoI have a Yubikey but I can't use it fully yet: - There is no Yubikey OTP app for the iPhone - Safari iOS does not respond to WebAuthn APIs (the apis are available but don't have any effect). I rather use plain Safari or Firefox, so Brave browser is not an option for me.
- jacekm 7y ago> does not respond to WebAuthn APIs Hmm, is it still the case? I don't have an iPhone, but after reading this post https://www.yubico.com/2019/09/yubico-ios-authentication-expands-to-include-nfc/ https://www.yubico.com/2019/09/yubico-ios-authentication-exp... my understanding was that WebAuthn will now work with all browsers, not only Brave.
- sebazzz 7y agoNo, I tried it. The APIs work normally from the web application perspective, but no prompt comes up to connect the security key. You also need to enable it from the experimental features page.
- allset_ 7y agoYubico Authenticator for iOS was released today.
- delogan 7y ago> Only iPads with Lightning connectors are supported.
- 0b0001 7y agoNow we have APIs for 2FA tokens in place. When will we get an API for password managers? That'd enable effective domain name checks and such.
- CGamesPlay 7y ago> TOTP risks - You could still fall victim to a fake website (or real one being proxied via man-in-the-middle like with Evilginx 2 and Modlishka) > Security key benefits - Even if the user willingly tried to log into a fake phishing site, the security key authentication would not work as the domain would differ. Why are security keys secure against man-in-the-middle attacks?
- kop316 7y agohttps://developers.yubico.com/U2F/Protocol_details/Overview.html https://developers.yubico.com/U2F/Protocol_details/Overview.... Via the U2F protocol, the browser embeds the URL and optionally the TLS Channel ID in the challenge, so a phishing website asking for a challenge will produce the wrong challenge (and response). Note this does not prevent an attack via webUSB (https://www.wired.com/story/chrome-yubikey-phishing-webusb/ https://www.wired.com/story/chrome-yubikey-phishing-webusb/ ).
- setheron 7y agoThere's no we ay to stop a full MITM though where maybe the State took over the certificate of a site.
- dfox 7y agoIf the Channel ID is included it stops MITM completely. In fact doing the authentication inside the secure channel in a way that depends on the key that is used by such channel is the best way to perform mutual authentication. In MitM case the authentication will just fail and passive attackers cannot learn anything about the identities used for authentication. Both SSH2 and many Windows-related protocols work in exactly this way.
- parliament32 7y ago>I use and love 1Password and pay for the cloud account Is it just me, or does a hosted password manager smell like an absolutely terrible idea to anyone else?
- bradstewart 7y agoThe convenience outweighs the risks for the vast majority of users. My parents need something that is available on all devices, syncs automatically, and requires no maintenance. You get a master encryption key that never leaves your device when setting up the account. Anything that touches their servers is encrypted with that key. You need that key to setup a new device (in addition to your username and master password).