3 ms·
This is strictly an upgrade from the old button though, as this is a single form of physical security vs zero. If used with a password, the key is only secure i
by CraftThatBlock 7y ago
This is strictly an upgrade from the old button though, as this is a single form of physical security vs zero. If used with a password, the key is only secure in computers with the password, AND it has to be you pressing.
Fingerprint are not very secure, but as this is meant to be only for physical access with the password, it's much better than before.
- munchbunny 7y agoThat's not the whole story. The use case we're all familiar with is that the YubiKey acts as the second (physical) factor. In that use case, this is great, because now you can opt to make the login three-factor: something you know (password), something you have (the fob), and something you are (your fingerprint). However, Yubico has also been pushing the password-less login angle. If you look at the FIDO 2/WebAuthn standards and the new capabilities in the current generation of YubiKeys (YubiKey 5's), there's a new capability called a resident key. This removes the dependence on passwords entirely. Currently you can protect that key with a password. I believe this new thumbprint reader allows you to unlock the resident key with a thumbprint. That's what would bring it to parity with built-in thumbprint readers on laptops. Passwordless login currently exists in the form of thumbprint readers (like on Thinkpads and those Samsung phones that recently showed they had a major flaw) and face recognition (laptops and phones). In the case of facial recognition, I think the convenience benefit is worth the security tradeoff. However, I'd be nervous about using passwordless fingerprint authentication on my YubiKey because that thing is so much easier to lose track of, and I don't trust fingerprint recognition.
- CraftThatBlock 7y agoI agree, I could've been clearer. I meant as a third for of authentication overall, with an additional password
- nullc 7y agoSingle factor use of a hardware token like this is a MASSIVE weakening of security against state actors that could compromise the token supply chain.
- AustinLin 7y agoIf you assume state actors can compromise the supply chain with impunity your Yubikey is the least of your concerns I would think. Why wouldn’t they just place a hardware implant in your computer :).
- nullc 7y agoThere is no potentially detectable 'implant' required in these cases, it can be sufficient to capture a factory initialized private key. The width supply chain of computers is enormous, and only a tiny fraction of computers available are interesting to compromise. This would make it astronomically expensive to compromise a significant fraction of all computers that are useful to compromise and the risk of detection would be fairly high. The market of security keys is relatively small and a significant portion are worth compromising, compromises there are much more effective. If state actors do not completely compromise the manufacture of these keys then they are extremely incompetent and derelict in their duties. Put another way, if the {pick your boogeyman state} government started issuing hardware cryptokeys and suggesting you use them as a single factor access to your servers, what would you think of that? Would your opinion be improved if they just didn't announce that they were the boogeyman state and instead did business under a cover company? Do you have any realistic means of determining that this isn't happening? "I let someone else generate my secret keys for me" is a failure at the most basic level of security, and that failure isn't removed by them also putting the secret keys in a potted, opaque, and unauditable hardware device. Yubikey as a second factor is a fantastic improvement-- it's a quite strong protection against attackers who couldn't compromise the keys. Yubikey as a single factor is simply key escrow with extra steps. Claiming that trusting the devices own 'fingerprint permission' is two-factor is deceptive since an attacker which has compromised the device's construction, design, or confidentiality of its state only faces one-factor security.