10 ms·
Using a Yubikey as a touchless, magic unlock key for Linux
- luizfelberti 6y agoThis is really cool, but I still feel betrayed cause when I read "touchless" and "contactless" I thought this was gonna use NFC
- aborsy 6y agoWhich NFC? Almost no laptop has nfc reader. I am not sure if the situation is different with PCs.
- kayodelycaon 6y agoIt’s not NFC, but macOS uses Bluetooth for Apple Watch unlocking. Sadly, it’s slow and unreliable.
- pqb 6y agoPersonally, I only know Dell Precision 7740 to have built-in NFC. I guess tablet-like / 2-in-1 laptops might also have it. Edit: Lenovo Yoga, Lenovo X1 Carbon have NFC too. Edit 2: Dell Precision 7750 also offers it. Edit 3: Models with pre-installed NFC module are very scarce, this site [0] lists only 204 occurrences among 7136. [0]: https://geizhals.eu/?cat=nb&xf=3710_NFC https://geizhals.eu/?cat=nb&xf=3710_NFC
- brian_herman__ 6y agoThis is a great idea!
- traceroute66 6y agoI stopped reading at the first paragraph: "At that point, anyone can take the key and use it for 2-factor authentication/SSH/GPG signing, so it’s not much better than just using a normal password.". If the author hasn't figured out you can assign a PIN to the keys you store on the Yubi, then I don't see why I should waste my time reading their rambling blog post. Good luck taking my Yubikey and trying to SSH to my kit. Won't do you much good without the PIN that is in my head. ;) P.S. You can also configure the Yubi to lock and mandate a PUK after too many wrong PINs.
- quadrifoliate 6y ago> If the author hasn't figured out you can assign a PIN to the keys you store on the Yubi, then I don't see why I should waste my time reading their rambling blog post. Try being a little nicer. If you feel that the blog post is a waste of your time, here's a revolutionary idea – don't say anything? There are 29 other posts on the front page, maybe one of those other ones will be worth your time. As it is, the UX of the poster's solution is totally different from yours; it enables a one-time, contactless authentication during login. Yours requires a ton of manual input every time the Yubikey is used for SSH. There is some different in the security models here, but the author's solution is broadly different from yours, and to me, much more convenient (I use a Yubikey with a PIN for work and it's kind of a pain).
- andreilys 6y agoI’m someone that often reads the comments before reading the article, so it’s helpful to know what people think is blog spam and what is actually worth reading.
- quadrifoliate 6y agoUnderstood. I'm making the claim that the OP's comment is both derogatory ("rambling", "waste of my time") and not relevant to the solution described in the article. Therefore, if anything, the comment is more deserving of being labeled spam than the article itself.
- wrkronmiller 6y agoSeconded. I think one of Hackernews’ biggest value-adds versus say Oreilly is the eagerness with which the commenters on this site will rip apart bad ideas/articles.
- war1025 6y agoI agree, but also you can be critical without being an asshat. It's better to comment from a perspective of "I bet you didn't know this" than "Ha, you're an idiot"
- gigatexal 6y agoi wonder if this would work for Active Directory logins which my AD connected linux laptop does
- Wohlf 6y agoI believe the Yubikey will function as a smart card for AD authentication.
- ComodoHacker 6y agoThe main drawback of this method if used daily would be broken USB ports.
- crote 6y agoI had the same concerns. Luckily, Yubikey also sells keys with NFC support. I now have a cheap NFC reader on my desk, and everything is now contactless.
- GekkePrutser 6y agoYeah besides contactless being an option as the other poster said (I use this too sometimes, especially on my phone), at work I use a cheap USB hub for this. When a port dies or becomes unreliable, I tape it off and use the next one. It can be really cheap as USB 2.0 is more than fast enough for a yubikey. I'm at 2 out of 4 ports dead now after 1,5 years on a $10 hub so it's not bad :) In addition, it's an iMac and the ports at the back are a nightmare to use. I taped the hub to the 'foot' of the iMac so it's much easier to use. I don't use this mode though but PIV + PIN.
- postalrat 6y agoI use the charging port on my phone pretty much daily and haven't had too many problems breaking the port.
- Xylakant 6y agoI’ve been using yubikeys for at least the last 2-3 years for all ssh/gpg operations and I have my key on my actual keychain so there’s extra weight on it and sometimes the key sits at a bit of an angle. Still, I have yet to break a single USB port on my ThinkPad. I’m a bit worried about USB-C though.
- dpifke 6y agoSpeaking from experience: the USB-C Yubikey will snap right off, without damaging the port (at least, on a ThinkPad X1).
- deadbunny 6y ago
- flurdy 6y agoSome time there was a similar tool that locked the computer via bluetooth if you walked away from the desk with your phone. It didn't unlock it which is fine, but it seems a better way to lock a computer if you forget rather than a timed screensaver after x minutes which leaves the computer vulnerable until then. (Mostly just from colleagues changing your wallpaper, or autocorrect...)
- jfb 6y agoThere used to be a Mac app called "Bluephone Elite", IIRC, that could do this for a very specific group of phones. It worked with my Sony Ericcson thing BITD.
- jpalomaki 6y agoWindows 10 has this feature [1]. Would be more useful if you could tune the required signal strenght. [1] https://support.microsoft.com/en-us/help/4028111/windows-lock-your-windows-10-pc-automatically-when-you-step-away-from https://support.microsoft.com/en-us/help/4028111/windows-loc...
- GekkePrutser 6y agoSounds good, but I'd really want to use a PIN with that. Otherwise anyone can take my key and walk up to the computer and unlock it. I wonder if there is something like pam_piv? I use PIV already for Mac & Windows... Suppose I should look for it myself :)
- aborsy 6y agoYou need a pin for GPG. Note that, that would protect only the gpg keys. Don’t forget to set a password also for the YubiKey Authenticator app. Otherwise I believe anyone who has your key would see the websites with which you have Fido U2F and use it.
- tialaramex 6y ago> Don’t forget to set a password also for the YubiKey Authenticator app. Otherwise I believe anyone who has your key would see the websites with which you have Fido U2F and use it. From what I can see YubiKey Authenticator is a TOTP authenticator. So that's completely orthogonal to U2F (and less safe, although more familiar to users who have things like Google Authenticator) With U2F non-resident credentials don't leave any trace. If somebody has stolen a working authenticator they'd need to guess sites at which its non-resident credentials would be valid and then try it.
- exabrial 6y agoPIV certificates are kinda meant for this
- kayodelycaon 6y agoI think the concept is really cool and it’s awesome that Linux makes it relatively easy to play around with authentication methods. I love this kind of stuff. But I’m also a pragmatist. While I run Linux everywhere I reasonably can, my daily driver is macOS and I can’t help but wonder if a fingerprint reader would be a better solution. On my Mac, the fingerprint reader can unlock the system immediately and works across the operating system for root access, including sudo. (There’s a pam module.) Locking can be done OS-wide using a keystroke (Cmd+Crtl+Q), touchbar button, or by closing the lid. Windows has had similar capabilities far longer than macOS.
- deadbunny 6y agoAs a daily user of Linux for the best part of a decade I'm curious where Linux falls short for you?
- Spivak 6y agoYeah, that same PAM works on Linux too. Non-Apple hardware isn't exactly known for shipping the best readers but they work well enough.
- kayodelycaon 6y agoThe major one is deep integration of applications with the OS. One example is any keyboard shortcut in any application can be remapped at the OS level. Dictation and services available almost everywhere text can be entered. Any text in almost any dialogue is selectable. Application dialogs like open and print are standardized. The print dialog is incrediably rich with functionality, in every application. This extends to integration with iOS devices and system hardware. The stock OS is ready out of the box with a full suite of integrated applications. While there are better versions of all of them, most are high quality. Though, I haven’t found a PDF reader better than Preview and Apple Notes is very hard to beat as a general note taking tool. The base OS has color syncing. I was able to hook up a professional grade printer, have the OS automatically install the drivers, and produce color accurate prints using Preview. The system print dialog allowed me to fully configure the printer. No specialized tools required. There’s even an iOS app that can do the same thing in a more limited fashion. Never had a driver issue or had to modify a configuration file to get hardware to work properly. (Have done GUI tweaks via defaults.) When it comes to specialized applications, there are a lot of excellent applications written specifically for macOS. Some come with iOS apps. (1Password is high on my list.) Due to the industries I work in, Microsoft Office is a hard requirement. Libre Office is not an option. Time machine has no equal when it comes to backups and restoring to new hardware. I haven’t done a clean install since 2008. In two hours I can completely clone my current machine. This is just a few of the many reasons I use macOS. Frankly, they are more important to me than openness of platform or deep control of my devices. That does not mean I don’t appreciate Linux. I love Linux. There is nothing better for servers than Linux. I have older laptops loaded with Linux but they are a hobby for me. Linux fills a very important place in the world. Frankly, the world needs open operating system and people who enjoy using it. But I have neither the time, expertise, or inclination to do so on my primary machine.
- SahAssar 6y ago> Yubikeys are great for security, but not when you leave them in your computer unattended. At that point, anyone can take the key and use it for 2-factor authentication/SSH/GPG signing, so it’s not much better than just using a normal password. Even after the edit at the top regarding PIN it still seems to not get the main point of a U2F token: It's physical. It's incredibly hard to extract secrets from it. It's local to where it physically is. If I have a password then there are probably a couple of services and people that could reasonably get to it either by hacking the service the password unlocks (in storage if its a really insecure service or in transit the next time I log on), or can extract it from my password manager/memory/browser or whatever. The point of a U2F token for me is to change the number of people who can reasonably authenticate as me from "everyone who has my password" to "everyone who have a physical key I keep within a reasonable distance from me that is incredibly hard to copy and has my password". U2F also validates auth origins quite a lot better than many other methods, although I guess that is not relevant to this argument. A hardware U2F token is not the end-all be-all security, but it reduces potential attackers a lot.
- Spivak 6y agoHonestly the threat of someone cloning the key is so minor that a USB stick is probably enough. If someone goes through the effort to make fake a USB stick with the right hardware ids then I've got way bigger problems.
- SahAssar 6y agoIf you are talking about a U2F usb stick I agree with you (I put "incredibly hard" instead of "impossible" there so that I don't get counterarguments with people reading memory with electron microscopes or similar). If you are talking plain USB mass storage for keys I disagree.
- ashtonkem 6y agoFor most of us, the inability for the key to be duplicated remotely is the primary design criteria, as most of us need to defend against low to moderate remote attacks (which is exactly SMS 2FA is bad). You have to be an incredibly high value target before "my opponents are willing to send people to try and steal my 2FA token from my person and clone it" is a probable risk. At that point you better be using all kinds of special equipment and techniques, as a Yubikey alone probably isn't enough. That being said, it's incredibly unlikely that someone would ever sell mass storage based USB credentials because: 1. Security products are marketed based on surviving the worst case scenarios. Nobody would buy a U2F token that is "good enough for the threats you probably face". 2. By the time you've hardened any USB device from remote cloning, you're probably already done most of the work to harden it against local cloning. Might as well complete the last bits necessary in order to get the marketing benefits from point 1.
- trishankdatadog 6y agoBTW, here is a handy way to quickly generate GPG keys (and set up git commit signing and SSH key derivation) on Yubikey: https://github.com/DataDog/yubikey https://github.com/DataDog/yubikey
- StavrosK 6y agoIf you only want to do SSH, that way is a huge hassle, way too much to do on machines you don't own/are using casually. If you can use newer SSH versions, they support FIDO2 natively: https://www.stavros.io/posts/u2f-fido2-with-ssh/ https://www.stavros.io/posts/u2f-fido2-with-ssh/
- Legogris 6y agoI don't think many people use GPG keys for SSH only (:
- trishankdatadog 6y agoSure, but most SSH servers probably don't support FIDO2 yet (GitHub didn't the last time I checked). Also, please sign your git commits.
- ashtonkem 6y agoA permanently attached Yubikey is not worse than a password alone, and is still superior to SMS 2FA. It still requires that an attacker know both your password and have physical possession of your machine. For the vast majority of users, this is sufficient protection from the threats that they face. The chance that someone both knows your password and is close enough to steal your yubikey is incredibly unlikely. If you’re the kind of person liable to get personally targeted for nation state level attacks, then you definitely are going to want to unplug your yubikey and keep it on your person. For the rest of us, a hardware 2FA token is enough to protect against a sim swap attack, which is probably enough.
- deleted 6y ago[deleted]
- Legogris 6y ago> liable to get personally targeted for nation state level attacks Groups also potentially at risk: * Targets for industrial espionage (you might not be interesting but your employer is) * Those believed to hold larger amounts of cryptocurrency
- stingraycharles 6y agoYeah I have this setup for quite a few years by now, and occasionally I question whether this practice makes sense. What does make it incredibly dangerous is that it also applies for eg “sudo”: if you don’t have any additional protection, it effectively means that any exploit in any app can be immediately extended to a local privilege escalation, as there is no additional protection in place. In other words, be careful what you wish for. :)
- tuananh 6y agoi dont get why it's better password and 2FA? leaving yubikey unattended, it will only require attacker to know the password (PIN).
- solatic 6y ago> If you’re the kind of person liable to get personally targeted for nation state level attacks, then you definitely are going to want to unplug your yubikey and keep it on your person. Maybe yes, maybe no. Do you have a backup YubiKey? If so, then you need to keep it in a separate location (i.e. don't defend against losing your keys by putting both your primary and your backup on the same physical keychain). Are you putting it in a safe? What safe can you buy that is sufficient protection against nation-state level attacks? How often do you check your safe to make sure that your backup hasn't been stolen? What process do you have in place to revoke and replace your backup YubiKey in case you do discover that the backup has been stolen (do you have a list of every website at which you ever enrolled the backup, and how do you safeguard the list)? IMO unless you are very seriously paranoid, you buy a "nano" in-slot YubiKey if your usage pattern targets a single machine, and a keychain YubiKey (with NFC) if you need portability between, say, your work laptop, your home desktop, and your phone. It's not a question of security but of your usage pattern.
- new_realist 6y agoSo anyone can take my Yubikey and use it to gain access to my computer without so much as a PIN? Is that a good idea?
- saghm 6y agoTo be fair, that's also how cars and houses tend to work
- new_realist 6y agoI prefer progress in the forward direction.
- dredmorbius 6y agoUntil recently, neither were typically Internet-connected.
- TwoNineFive 6y agoHey author, why did you use the words "touchless" and "contactless" when it's not true and not even relevant to the technology being used? There's something strange going on here, like this article was written by AI or something. It's using words out of context, or just making plainly/obviously false statements.
- rossjudson 6y agoSeems like a bad idea. Requiring a touch means it's much harder to trigger the key through software alone -- or maybe impossible. So someone has to actually be present at the machine. This is particularly important when, for whatever reason, the machine you can actually put your hands on is actually a gateway to other machines. You can ssh tunnel all you want, but somebody still has to physically touch the key for it to authenticate. Naturally, that only works if you authenticate at each level, and if you do not trust other levels. The way we use them at Google, the keys are associated to particular machines and human accounts. You can't just remove a key from one machine and stick it into something else. It is the combination of the machine and the key that is enabled. A key can be deregistered/wiped, and assigned to a different machine...but you need to be properly logged in to make that happen. In the context of a corporation that is relatively straightforward, but perhaps for personal use it is less so. Actually, without the right infrastructure in place, it's quite likely to be a lot more complicated.
- Pneumaticat 6y agoThanks everyone for the feedback on Yubikeys being stolen! I've tried to summarize it all in a footnote, and downgraded the severity of my original starting paragraph. Thanks for reading!