5 ms·
> I wanted to find out how secure people think this is It depends on what do you compare this with. PKCS/OpenPGP smartcard is protected by a PIN (6 digits min,
by Leace 7y ago
> I wanted to find out how secure people think this is
It depends on what do you compare this with. PKCS/OpenPGP smartcard is protected by a PIN (6 digits min, 3 tries and it locks itself out) and then touch on each use (with Yubikey).
U2F on the other hand it just protected by touch so anyone having the token can authorize themselves. (Sites usually use it in conjunction with username/password that is "something you know").
On the yet another hand I didn't review the implementation and would welcome corrections here.
- GhettoMaestro 7y agoGood point. When I used a Yubikey as a Smartcard it did in fact prompt for a passphrase. But that was via PKCS/SmartCard method, not U2F.
- ecesena 7y agoU2F/FIDO2 supports user verification (UV) in addition to user presence (UP). So you should be able to do the same, but I haven't tested if the current implementation supports it.
- tialaramex 7y agoTheir own documentation suggests these are the same thing and both refer to the need to press a button or close a contact or whatever: Generically, the term “User Verification” may also refer to this “Test for User Presence” from e.g. https://fidoalliance.org/specs/fido-security-requirements-v1.0-fd-20170524/fido-authenticator-security-requirements_20170524.html https://fidoalliance.org/specs/fido-security-requirements-v1...
- ecesena 7y agoWeird, this spec has a little bit of a different terminology. I think it's better to refer to CTAP2 or WebAuthn directly. UV refers to PIN or biometric, it's in addition to UP. https://fidoalliance.org/specs/fido-v2.0-ps-20190130/fido-client-to-authenticator-protocol-v2.0-ps-20190130.html https://fidoalliance.org/specs/fido-v2.0-ps-20190130/fido-cl...
- Boulth 7y agoNote that CTAP and WebAuthn are newer and although they contain U2F for backwards compatibility reasons U2F doesn't contain CTAP2 and WebAuthn. U2F is also surprisingly simple protocol (two specs on FIDO site).
- ecesena 7y agoYes, and exactly because FIDO2 is backward compatible with U2F the definition of UV can't be ambiguous, otherwise you could have older U2F keys that pretend to do FIDO2-UV when in fact they aren't.
- justincormack 7y agoYubikey just announced a key with a fingerprint reader today.
- jolmg 7y agoBesides the point that it wouldn't be a secure replacement for a password/PIN, I wonder if it would have support for multiple valid fingerprints. Some time ago, I got cut on my finger and was having some trouble getting my fingerprint recognized. It would suck to get locked out of stuff because of a cut.