5 ms·
I'm really excited to see more and more people talk about FIDO2. If you're interested about this topic, I gave a talk about it yesterday: https://news.ycombinat
by spiridow 6y ago
I'm really excited to see more and more people talk about FIDO2. If you're interested about this topic, I gave a talk about it yesterday: https://news.ycombinator.com/item?id=23689606 https://news.ycombinator.com/item?id=23689606
- StavrosK 6y agoThat's very useful, thank you! I've been looking for something that goes into a bit more detail, so your talk is timely.
- jjoonathan 6y agoHere's a browser compatibility matrix (I know, OP is about SSH). FIDO2/U2F Just Works in: Chrome on Windows Firefox on Windows Chrome on Mac Firefox on Mac Chrome in Ubuntu 20 Firefox in Ubuntu 20 Wall of shame (FIDO2/U2F does not Just Work in): Safari EDIT: it does work out-of-the-box in Ubuntu 20, my bad.
- microcolonel 6y agoJust Works in Chromium and Brave on Arch Linux.
- jjoonathan 6y agoWith or without udev tweaks? That has been the major caveat on linux in recent times.
- microcolonel 6y agoI have no personal udev rules for my Yubikeys, just whatever ships with Arch.
- xenophonf 6y agoI haven't had any problems using my Yubikey in U2F or PIV modes on Ubuntu 20.04.
- jjoonathan 6y agoConfirmed and updated, thanks! The fact that it didn't work out-of-the-box in Ubuntu 19 (needed a udev tweak) and a failing USB port on my laptop gave me the impression that it also didn't work out-of-the-box in Ubuntu 20 (which I booted from a USB key, hence the good port was unavailable), but I just tried it using my laptop's good USB port and a hub and I can now confirm that it works out-of-the-box in Ubuntu 20.
- StavrosK 6y ago"Passwordless" mode unfortunately doesn't work for me in Firefox, I implemented it on https://www.pastery.net/ https://www.pastery.net/ but I'm not sure if I did something wrong. Chrome works fine, though.
- seqastian 6y agoSafari 14 should change that though. https://developer.apple.com/documentation/safari-release-notes/safari-14-beta-release-notes#Authentication-and-Passwords https://developer.apple.com/documentation/safari-release-not...
- lxgr 6y agoIt already works with external FIDO2 compliant authenticators on Safari 13 (iOS 13.5 and macOS 10.15.4).
- tialaramex 6y agoIn a browser what you want is WebAuthn, U2F is an older never technically standardized hack and should not be used for new implementations. New web sites should do WebAuthn to enable this functionality, here's a guide someone else wrote that I found helpful in talking about the moving parts to actually implement this: https://webauthn.guide/ https://webauthn.guide/ Firefox's WebAuthn implementation isn't as complete as it would ideally be, but it does have a nice feature of asking the user whether to give out the somewhat privacy-infringing "attestation" from a FIDO2 device when it is requested by a web site. IMNSHO ordinary web sites, especially where a second factor isn't even mandatory, should not be asking for attestation and I always refuse.
- StavrosK 6y agoOh is that what the "anonymize this key" is? If the website requires attestation, authentication might fail, but no website should require attestation, maybe unless you explicitly got the key from them (like a bank).
- lxgr 6y agoWebsites should absolutely be requiring attestation. The attack scenario here is malware on your computer pretending to be a hardware authenticator (during sign-up or 2FA enrolment) but really just emulating one in software.
- tialaramex 6y agoIn this scenario bad guys are currently authenticated as you (otherwise they can't do enrolment) and can do whatever they want but, perversely, they decide what they want to do is... obtain the ability to authenticate as you later in a traceable way. I don't buy it. If you're a James Bond villain and the plot's resolution needs to be saved for the final reel then this makes sense, you can't blow up the world 40 minutes into the story 'cos the audience knows that isn't the end. But real crooks don't want to build suspense, they're going to jump to the part where they win. Why play this long game?
- 6y ago
- conradev 6y agoI've been using my YubiKey 5Ci in Safari on macOS and iOS since macOS 10.15[1] and iOS 13.3[2] (which came out several months ago), and Safari supports FIDO2 + WebAuthn just fine. [1] https://developer.apple.com/documentation/safari-release-notes/safari-13-release-notes https://developer.apple.com/documentation/safari-release-not... [2] https://developer.apple.com/documentation/ios-ipados-release-notes/ios-ipados-13_3-release-notes https://developer.apple.com/documentation/ios-ipados-release...
- jjoonathan 6y agoConfirmed, WebAuthn works on Safari, MacOS 10.15.5, and https://demo.yubico.com/ https://demo.yubico.com/ . My mistake was to assume that AWS saying "Your browser does not support U2F security keys." meant that Safari didn't support U2F keys. Given AWS's well-earned reputation for half-assing things I really shouldn't have trusted their assessment, but I did. My bad.