20 ms·
Pressing YubiKeys
- natvert 6y agohaha, this is great! i was thinking about making something similar to skip youtube ads on my ipad!
- jdlyga 6y agoI thought about this, but I ended up just paying the $6 per month for YouTube Premium (student discount)
- drewbug 6y agoThis lets malware trigger one time code emission...
- Firerouge 6y agoNot in practice. The odds any malware would both locate this api, and actionably utilize a generated otp, is slim to zero.
- gruez 6y agosounds like security through obscurity.
- vernie 6y agoRight. And that isn't a problem for some threat models.
- gorkish 6y agoTo a robot, the act of moving meat into physical proximity with a switch might be considered to be an equally obscure action. As a component of a 2-factor system to prove token possession, either seems quite adequate. The use of U2F tokens as single factor auth seems to have promulgated thanks to this implicit 3rd factor keeping the situation moderately at bay. I posit that this is largely the same reason that keys and locks remain relatively secure despite that almost all of them are trivial to bypass or duplicate. The physical access bit is just so damn inconvenient for the typical modern white-collar criminal.
- walrus01 6y agosee also: https://smallhacks.files.wordpress.com/2012/11/camera.jpg https://smallhacks.files.wordpress.com/2012/11/camera.jpg
- bertrandom 6y agoI've made one of those, too! https://www.flickr.com/photos/bertrandom/4975638961/ https://www.flickr.com/photos/bertrandom/4975638961/
- 0xCMP 6y agoA proper hack
- anonova 6y agoAdaprox has various "finger bots" for those who don't want to build their own: https://www.adaprox.io/ https://www.adaprox.io/
- gorkish 6y agoThis is pure brilliance.
- punnerud 6y agoThere is also MicroBot: https://microbot.is/push/ https://microbot.is/push/ I used it for testing smart meters in Norway, so we did not need to run to the lab to trigger events. The best part is that the whole menu is interactive by just one physical button, a great job for a Bluetooth button pusher + Python. It is also capacitive so it work on the phone screen, and YubiKeys (?)
- WrtCdEvrydy 6y agoCan you get to the 'buy now' shop on that site?
- newman314 6y agoThe support site appears to have an expired cert. Are they still in business (or just limping along)?
- golem14 6y agoThis is all great, but not steampunk enough ;) Check this out: https://www.youtube.com/watch?v=l-fcfGwepog https://www.youtube.com/watch?v=l-fcfGwepog Now, electrifying that would be neat!
- f0ff 6y agoCongratulations, you've defeated the purpose of having a YubiKey
- xkcd-sucks 6y ago> the purpose of having a YubiKey Compliance?
- RegnisGnaw 6y agoExactly. At one of my work places, we needed 2FA to log into a vendor portal. So we stuck the username, password, and TOPT in Vault which is protected by corporate AD password only.
- f0ff 6y agoI'd hazard saying that the purpose of a YubiKey is to provide two factor authentication. A YubiKey acts as an item, posession of which implies identity. When you allow for the YubiKey to be activated without human interaction, it's moved from domain of posession into the domain of knowledge - identifying party needs to know where to knock, not to possess they key. It's no better than appending the URL at the end of your password. If you allow for a YubiKey, or any other physical artifact in that matter, to be remotely invoked it negates its utility as an authentication factor in the physical domain.
- inlined 6y agoIf they made the uri SSL with fixed certs it’s still a “something I have” factor IMO.
- Dylan16807 6y agoIt depends on what protects the key. If the problem is being unable to duplicate it, you could protect remote access with a different YubiKey or some other second factor. And the setup in the article isn't even remote access. If the only way it can be triggered is a local button press, you're golden.
- tegiddrone 6y ago
- gcommer 6y agoThis could be handy for automating a real world end-to-end test of a yubikey auth flow.
- hugs 6y agoI got into robotics and have been able to do it professionally for several years precisely because it's a useful way to automate real world end-to-end testing.
- infinitybeyond 6y agoYour robots are exactly what I thought of when I saw this post. What kinds of common and uncommon use cases are you seeing at Tapster? Good meeting you at the FLL competition last year! -Cody
- vnxli 6y agoThis is some cowboy engineering and i love it. totally shooting from the hip, but still finishing up with a nice long-form post. like other comments mentioned this is super impractical but that's not the point. building a robot finger to push a button at the push of a button is a hilarious saturday afternoon project good job bert!
- el_oni 6y agoIt's one of those projects that lets you flex your problem solving muscles in a low stakes environment. Taking "I wonder if i could..." and running with it
- GekkePrutser 6y agoThe whole point of this touch to sign is that it can't be hacked remotely :) and you can just turn it off for most modes.
- Jnr 6y agoOr you could just disable the requirement of using the touch.
- shrubble 6y agoWhy did he not call it The Finglonger?
- Raphmedia 6y agoThe final thoughts at the end of the article are amazing: "Why not just press the button?" ... "Don’t you get it? This button BAD, but this button GOOD. Me want to press GOOD button."
- jeroenhd 6y agoThe obvious next step is to plug this into a server and control it through USB over IP. Call it "remote, centrally controlled 2FA" and your manager will love it!
- dheera 6y agoConsidering many services only allow one YubiKey or only one TOTP authenticator ... I might actually need a short term solution like this to beat the 2FA on those services. Otherwise what happens if I lose my key on the road? The 2FA services that allow >1 YubiKey are good, I can have a backup key locked up some place and use them as intended.
- lukeschlather 6y agoIt would be better to use a software TOTP authenticator with backups. You could also store multiple encrypted copies of the TOTP secret encrypted with different Yubikeys. I don't know if there's any software that does this automatically and momentarily decrypts the TOTP secret into a secure memory location when you need it. That preserves... most of the benefit of 2fa.
- dheera 6y agoStoring copies of a TOTP secret is as good as just having 2 high-entropy passwords and saving multiple copies of one of them in clear text, which is not more secure than having 2 high-entropy passwords and not storing them anywhere, and which is equivalent to just 1 doubly-high-entropy password not stored anywhere. The fact that you can store copies effectively defeats the purpose of 2FA. One of the reasons to have multiple YubiKeys is that if I lose one on the street I can just login to all my services with my backup key, disable the lost/stolen key, and buy and register a new key. Whereas if someone got a hold of your TOTP secret, ehhh ... you might not necessarily know for a while.
- lukeschlather 6y agoI meant backing up TOTP keys is better than: > to plug this [Yubikey] into a server and control it through USB over IP. Obviously multiple Yubikeys is the only real solution.
- cproctor 6y agoNow we need a yubikey captcha.
- anfractuosity 6y agoReminds me of this, "The Tinda Finger Swipes Right On Tinder So You Don't Have To" https://www.youtube.com/watch?v=IaoDfOaYF4w https://www.youtube.com/watch?v=IaoDfOaYF4w
- conk 6y agoNice build but over engineered. You could achieve the same result by taping a piece of aluminum foil, or maybe even a wire to the capacitive sensor and connecting it to ground through a relay. Use the ESP8266 to toggle the relay when you want to simulate a button press.
- suprfsat 6y agoBut that wouldn't have a 3D-printed finger
- Godel_unicode 6y agoYou're missing a very important core requirement: it has to look cool.
- srtjstjsj 6y agoThat violates corporate IT policy which expressly instructs me to touch the key with one of my fingers.
- inlined 6y agoTechnically the author is using of their fingers. Wasn’t the model Creative Commons?
- sxp 6y agoWhen I was at Google around 2012, the company had a custom 2FA dongle that detected motion rather than touch. An engineer who had remotely ssh'd into their workstation needed to 2FA and realized that they could send an SMS to their phone, cause the phone to vibrate, and trigger a false 2FA event on the dongle. (Or maybe they got their computer to play a loud noise. I forgot the specific details.) Similar to this fake finger, it was a cool hack at the time but defeated the purpose of 2FA.
- np1810 6y agoMore on defeating 2FA, during my internship at Amazon I created a grease monkey script that would store 'n' yubikey codes and paste them automatically whenever browser asked for a yubikey code and this worked flawlessly because afaik yubikeys code have No Expiry... they just have to be used in order of their generation... I highlighted this issue of No Expiry of yubikey codes but no one took it seriously...
- michaelt 6y agoYubikeys don't have an onboard battery-backed clock, so they can't give out timestamped responses.
- np1810 6y ago> Yubikeys don't have an onboard battery-backed clock, so they can't give out timestamped responses. Ok got it and we can't trust the host PC clock or any web based clock via host pc...
- Cerium 6y agoA little off topic: Does anyone know of a way to get the results of a yubikey press into a remote desktop session? I frequently remote desktop into laptops that are in arms reach. If I need to use the yubikey, I have to remove it and plug it into my desktop and press it, since it acts as a local keyboard.
- somedude11 6y agoUSB Redirector or USB Redirector RDP incentivespro.com
- Cerium 6y agoThanks!
- Thorrez 6y agoWouldn't a local keyboard type into a remote desktop session? If a local keyboard can't type into a remote desktop session, the remote desktop session sounds mostly useless.
- Cerium 6y agoThe local keyboard attached to the remote computer.
- Thorrez 6y agoI don't usually RDP to machines withing reach of me, I would prefer to use a KVM. Also I usually keep a security key in my local machine. But I guess for convenient monitor sharing it could be useful to RDP into a machine within your reach. What is likely an actual problem though is if your security key uses U2F and you have it plugged into your local machine.
- agl 6y agoYou can just glue a wire to the touch plate and connect it to ground when you want to simulate a touch.
- paxys 6y agoI would personally not wire any amount of current to a USB peripheral connected to my MacBook.
- unwind 6y agoSwitching a wire between mid-air and ground passes 0 current in both states which sounds like a pretty safe amount, though.
- threadpiper 6y agoIts like grounding it, same thing you do when you touch it. pretty safe no?
- GeertB 6y agoWhy not just keep the wire attached to the Yubi-key, but leave it electrically floating (high-impedance state) and have the board ground it whenever it needs to be pressed? No need for mechanical triggers...
- driverdan 6y agoBecause that wouldn't get as many upvotes.
- doom2 6y agoReally liking the SA 1976 key set! What is the board?
- bertrandom 6y agoIt's a WASD v2 TKL, I have two!
- johnnyAghands 6y agoIs there a SOAP interface for this? We're interested in rolling this out where I work.
- rgoulter 6y ago"Why have an Applescript call a shell script? I found that when I launched the shell script directly from Karabiner Elements, it opened a new instance of Terminal.app and took focus away from the window that is prompting for the YubiKey. This causes everything to run in the background." Does anyone know why that is?
- mattnewton 6y agoWhy not just put the yubikey in a housing with a mechanical switch above it and screw it into the side of your keyboard?
- notRobot 6y agoCouldn't you just skip the motor, and have a wire always touching the contact, and use a relay to connect the other end of the wire to ground?
- 1970-01-01 6y agoThis is as impressive as it is pointless. You are treating the symptom and not the problem.
- AceJohnny2 6y agoTangentially: > And if you work on a political campaign or as a journalist, you should definitely have one (or something similar). It's tough, tptacek & idlewords have been facing an uphill battle with that: https://idlewords.com/2019/05/what_i_learned_trying_to_secure_congressional_campaigns.htm https://idlewords.com/2019/05/what_i_learned_trying_to_secur...
- mcdee 6y agoA slight aside, but so many of these keys seem to have the touch point / button applying force perpendicular to the direction of insertion, I wonder if there is any long-term potential to cause damage to the USB interface.
- gabeio 6y agoI have one of those you don't need to _press_ it seems the conduction of the finger is "key" (haha, sorry). But yeah I agree if you are pressing it _hard_ it will likely damage the usb port especially considering it doesn't have the housing around the contacts which I would say might protect the port a bit better, probably translating the force not to the contacts.
- ShakataGaNai 6y agoThis reminds of back in the olden days (when SMS MFA was still an "OK" thing to do) we needed shared MFA for IT Admins of various SaaS apps. We setup a dedicated phone, duct taped to the wall, to get these codes and push them to hipchat (via Tasker & NodeJS). One of my team members did a write up about it years ago: https://obviate.io/2015/04/16/making-of-the-mfa-phone-because-twilio-is-too-easy/ https://obviate.io/2015/04/16/making-of-the-mfa-phone-becaus...
- dokem 6y agoThis is a great example of writing without having a clear idea of who your audience is.
- humanfromearth 6y agoThe keyboard is sooo cool!
- crispyambulance 6y agoYeah, it's sweet. "1976" keycaps. https://drop.com/buy/nineteenseventysix-sa-keycap-set https://drop.com/buy/nineteenseventysix-sa-keycap-set
- etaioinshrdlu 6y ago"If you work in tech, you probably have a YubiKey" The author must live in some kind of bubble. This may only be true at Big Tech companies or other companies with a atypically strong security focus.
- justfortechnews 6y agoAgreed - feel like I rarely see any YubiKeys outside of my coworkers' laptops.
- tuatoru 6y agoUsed to have some (actually, I still do, in a drawer) but gave up on them several years ago after random mysterious failures - just going dead after a few months. I hope for their customers' sakes they have solved their reliability problem.
- fmajid 6y agoI have four. One is clearly insufficient, you need a backup.
- bajsejohannes 6y agoYeah, that seems a little myopic. I've worked at more places without YubiKeys than with them. Edit: To be clear, I've had plenty of _other_ 2FA devices.
- bdamm 6y agoPhysical security tokens are both as old as dirt and the hot new replacement for passwords.
- CyberRage 6y agoIt seems like you don't understand the main advantage of these types of security tokens. Rogue trigger of a security token isn't really an issue when using the recommended U2F standard. U2F uses the domain as part of the challenge-response in U2F so that phishing\spoofing attacks can be defeated.
- suprfsat 6y agoYubikeys can perform many functions; the one in the article is an OTP which can be accidentally pasted into Slack.
- Thorrez 6y agoYes. But the main insecurity isn't accidental pastes, it's being phished. The company the author of this article works for needs to switch to U2F.
- Spivak 6y agoIf the only phishing protection you find meaningful for 2FA tokens is domain matching then any extension-based password manager like Bitwarden will work with far less hassle than needing a physical token or your phone.
- Thorrez 6y agoJust hope your password manager's password doesn't get phished. > or your phone. Using your phone for 2FA doesn't provide any phishing protection that I know of. What realistic attacks is a non-U2F Yubikey protecting against that TOTP (Google Authenticator) won't protect against?
- fmajid 6y agoHe never heard of a solenoid?
- crispyambulance 6y agoSolenoids are too abrupt for a "finger-push" actuation. The rack-and-pinion is a very good approximation
- codegeek 6y ago"So.. you built a button that you press that will press a button? Why not just press the button?” which was a bit infuriating because they clearly missed the whole point. “Don’t you get it? This button BAD, but this button GOOD. Me want to press GOOD button.”" This is gold.
- djhworld 6y agoReally enjoyed reading this post thanks. It makes me laugh that such a small problem (pressing a yubikey at an awkward angle, which sometimes doesn't register properly) can be solved with such a delightful over engineered solution.
- sarah180 6y agoThis reminds me of something that happened at a company I worked at maybe ten years ago. An employee was fired for setting up a webcam that pointed at his 2FA key generator so he could log in remotely without having to carry it around. Hacker mentality, but not in a way that won him the respect of the security team.
- djsumdog 6y agoAt work we use to use the old Yubi keys that were nice and long and had a good contact areas. Then they switched to the nanos and wouldn't reprogram the old ones (or even order the larger ones of the same generation, or let us pay for them ourselves). You can do the entire OTP entirely in software. Just be sure that the location you place the secret is encrypted: https://battlepenguin.com/tech/replacing-okta-verify-with-open-source-software/ https://battlepenguin.com/tech/replacing-okta-verify-with-op...
- slaymaker1907 6y agoPersonally, I just use Keypass since it can do TOTP very easily. It's not the best 2FA since it stores the second factor alongside the passwords, but you could fix this by having two databases.
- Spivak 6y agoI don’t really care about this one too much because if you got a copy of my pw database and knew the password you have enough access to remove the 2FA on my stuff. Like there is literally 0% chance I’m going to let myself get permanently locked out of my accounts if my keys and phone get stolen.
- Havoc 6y agoDoes the yubikey sense both force AND capacitative touch? Cause if it's only capacitative there is an easier way: https://www.youtube.com/watch?v=JDgDMBquBw0 https://www.youtube.com/watch?v=JDgDMBquBw0
- paledot 6y agoI'm not convinced "an easier way" is what the author was going for.
- pdxpatzer 6y agoI would place the yubikey on top of a small squared base made out of Sugru, therefore elevating it and making it easier to press.. If you are concerned about the stress on the usb port then you use one of those "right angle usb cable" short cables available on amazon.
- skizm 6y agoThe Bloomberg terminal uses a piece of hardware that generates 2FA tokens, but requires you to scan your fingerprint each time. So we need a fake finger that also has my fingerprint, and a webcam pointed at the 2FA hardware, so I can just get my auth keys remotely and not need to carry around another dongle.
- wrsh07 6y agoWays they could solve their problem without significantly compromising security: 1. Plug the yubikey into the monitor 2. Use an extension cord (as they did) 3. Switch back to an otp app (eg Google authenticator or Duo) 4. Credit to conk [1] or agl [2]: extend the conductivity via conductive foil or other material, connect to ground to simulate touch Ways you can improve convenience while reducing security: 1. This! 2. Disable 2fa (credit to another commenter) If 2fa is required by your company, circumventing it by eliminating the security benefit should be severely reprimanded. Why not build a different shitty robot? [1] https://news.ycombinator.com/item?id=24664842 https://news.ycombinator.com/item?id=24664842 [2] https://news.ycombinator.com/item?id=24664881 https://news.ycombinator.com/item?id=24664881
- ehsankia 6y agoYep, don't most of these work with conductivity? I just hacked something together using a paperclip and it works great.
- yoz-y 6y agoA colleague has a chain made of paperclips dangling from the back of his screen. For auth just poke the chain, looks cool and works great.
- dannyw 6y agoSecurity isn’t binary. This mechanism is more secure than no 2FA, because off the shelf malware isn’t gonna prod around your local network and look for a self built finger contraption. Furthermore, if someone does trigger it, the thing will move and you’ll hopefully realise you’re haxx’d.
- geocar 6y ago> Security isn’t binary. I hate that people say that. By adding some security (protecting against some threat) to another security (protecting against same threat) you gain no security, after all: 1+1=1 in binary, so security is binary in this way as well. By protecting the same thing with two different security mechanisms, you have multiplication, and in binary 1×0=0 so security is binary in this way. And so on. Security is about identifying threat-actors and devising cost-based challenges that exceed the value to others of compromise. In that way, it is absolutely a binary thing -- you are either secure from those specific threat-actors or you are not. It's a real problem that without perfect knowledge, you don't actually know if you are secure from those threat-actors: Someone can discover a cool factorisation trick, or your computer might make weird noises when multiplying certain numbers, or it might allow authenticated users faster responses than unauthenticated ones. Threat-modelling in the face of those kinds of thing is nearly impossible, but even against basic stuff (the stuff we already know) it can be really hard. For these reasons and more, weakening some security in what you may perceive as a small way can actually be absolutely catastrophic to the security against the intended threat-model. So don't do that: Start from the other side, decide what you're trying to protect and from whom, and convince yourself that they really can't gain anything with what they've got. Script kiddies using a ten year old version of metasploit? The finger is probably safe for all the reasons you're thinking, but if they find a way in, someone else is going to strace/gdb/dtruss all the things and find you've got a lot of secrets in RAM - if any of those belong to an even higher-value target, you can bet that is automatically harvested, collected, and shipped back to "home base" for use. > This mechanism is more secure than no 2FA, You can't meaningfully say more or less secure without saying who the threat-model is. For threats I worry about, this is much less secure. I also believe that's true for most yubikey users, including the ones with the technical ability to do something like this. > the thing will move and you’ll hopefully realise you’re haxx’d. If the yubikey cannot be triggered by my PC because there isn't a wire connecting the two together, then there is zero risk from a remote attacker who does have access to my PC -- unless you believe the airgap grants you nothing in the first place. I mean, I hope the airgap means something, but I don't hope that I will always be awake and in front of the finger paying attention to its gyrations and undulations.
- taldo 6y agoUrban myth: somebody taped a hotdog to the CD drive tray of their workstation, and put the yubikey right in front of it. Then, whenever they needed to touch the YK while not physically in front of the workstation, a quick `eject /dev/cdrom` did the trick ;)
- walrus01 6y agoIt's all good until you consider the need to periodically replace the hotdog every day or two, as it gets rotten at room temperature.
- taldo 6y agoWell, considering that you don't have to actually be at your desk anymore, you can let it rot for a couple of weeks between replacements. Or use some other material with similar conductivity and capacitance characteristics.
- JxLS-cpgbe0 6y agoYou just need to use a meat product that's so full of preservatives it can't possibly rot https://interestingengineering.com/mcdonalds-burger-survives-20-years-and-still-looks-fresh-off-the-grill https://interestingengineering.com/mcdonalds-burger-survives...
- dmm 6y agoA McDonalds hamburger patty is just beef, salt, and pepper. It was preserved by an environment that allowed it to dry out before spoiling.
- panda88888 6y agoAny capacitive stylus would probably work.
- OJFord 6y agoif mount | grep cdrom ; then echo hotdog else echo nothotdog fi
- sedatk 6y agoPresses, either accidental or through phishing, with YubiKeys can leak identity, I wrote about it before. Disable OTP mode if you're not using it. https://medium.com/hackernoon/avoid-leaking-your-identity-with-yubikey-92539b6608a https://medium.com/hackernoon/avoid-leaking-your-identity-wi...
- dzhiurgis 6y agoGoogle won’t let you setup 2FA without adding a phone number which kind of sets you up for sun swapping attack by design... My biggest beef is lack of NFC in MacBook. I wan’t a key in card factor because who the hell has keys these days. Maybe add hardware button on the card. It would work on on mobile and laptops. Banks could use their own credit cards for logging in...
- tialaramex 6y agoIf you've got adversaries doing a sun swapping attack you are in a Rick and Morty episode not the real world. I can't swear Google has never known one my phone numbers in the many, many years I've had an account, though they don't have one recorded now. However I can tell you with certainty I have three WebAuthn authenticators, and no SMS-style 2FA authorised on my Google account now.
- dmm 6y ago> If you've got adversaries doing a sun swapping attack you are in a Rick and Morty episode not the real world. It happened to Jack Dorsey. And attacks tend to become easier over time. Any employee of an at&t store could do it to you right now. The reason we know Dorsey was the victim of a sim swap attack is probably that he's important enough that when he was hacked he couldn't be dismissed with the "You probably messed up and leaked your password" dismissal.
- tialaramex 6y agoNo, Jack Dorsey suffered a sim swapping attack. Those happen here in the real world, but the post my joke was aimed at wrote sun swapping. Swapping suns isn't a thing outside of fiction. As to me, since you made it personal, I'm sure somebody at an AT&T store could attempt SIM swapping but they might have trouble because the system won't give them my number from a completely different numbering system (different county) without a code they don't have. If you socially manipulate your way into getting a transfer out code (good luck with that, but I'm willing to accept it could happen) then the big problem is I don't use SMS 2FA, as I wrote in the comment you're replying to, so it's a dead end.
- KerryJones 6y ago> If you work in tech, you probably have a YubiKey That is a gross overstatement. As someone who works for a pre-IPO startup and been in the bay in various startups for a number of years, I'd hazard that only 5-10% of the engineers had YubiKey, let alone "work in tech". Whether or not we _should_ is another question.
- miked85 6y agoThis seemed odd to me as well - anecdata, but I have yet to work at any company that uses YubiKeys, I have only heard that FB does.
- asymptotic 6y agoFWIW Amazon / AWS also use YubiKeys.
- Arainach 6y agoGoogle as well. (Physical security keys, at least - I make no specific statement about branding)
- solarkraft 6y agoI think they would be Titans.
- MichaelMoser123 6y agogoogle doesn't use google authenticator? How odd.
- bradknowles 6y agoGoogle and Amazon are both well known to use hardware that is similar to a Yubikey, but not exactly the same.
- kyrra 6y ago
- trashburger 6y agoWouldn't a really long insulated cable that you touch with your finger work? It would just carry the capacitance, and it would probably cost pennies.
- nuker 6y agoApple Touch Id on Macbooks is pretty much YubiKey replacement, right?
- PascLeRasc 6y agoMaybe (don't have a new enough Macbook) but SoftU2F is the Yubikey replacement I've been using: https://github.com/github/SoftU2F https://github.com/github/SoftU2F
- gouggoug 6y agoThe one thing I don't understand with Yubikeys: doesn't leaving them plugged in at all times in your computer (which the form factor highly encourages you to do) completely defeat the purpose?
- aborsy 6y agoNo, you need to press the button. In situations where laptop is not under your control, you can remove it.
- deleted 6y ago[deleted]
- ecesena 6y agoSecurity keys protect against phishing, in addition to account takeover. Say you click on a link that looks like Google but it's not. You enter your credentials -> these are now in possession of the attacker. If you have 2FA enabled AND you use a security key, the key digitally signs the hostname of the site you're browsing. This second factor won't be valid on the real google.com site because it was created on the phishing site. Phishing protection is a core feature unique to security keys, and it's completely independent whether you keep the key in your laptop or you bring it with you.
- gouggoug 6y agoI did not know that "detail"; it totally makes sense though, thanks!
- blueblisters 6y ago> If you have 2FA enabled AND you use a security key, the key digitally signs the hostname of the site you're browsing. How does this work? Does the browser talk with the key? I thought the key is primarily an input device.
- ecesena 6y ago
- supernova87a 6y agoI thought the article was going to be about how there was a serious real vulnerability in the hardware and some remote attacker could spoof the Yubikey being touched. Then the article turned into a joke.
- geocar 6y ago> iTerm2 has a feature called Triggers, which can execute actions based on text matching a regex in your terminal. So we could write a regex to listen for “Yubikey for” and have it run the same script, eliminating the need to press buttons altogether. Don't do this. Actually seriously, don't do most of this. The fact that your computer cannot induce the yubikey to provide its key material (or evidence of the key material) is where it gets "security" from in the first place. As soon as someone can convince your computer to do something there's an increased chance they can get it to do something else. Some suggestions: - Wire the F14 key up separately to "the finger" (and not to wifi) - Use a yubikey simulator[1]. If your sysadmin won't trust you with the key material inside the yubikey so you can use a simulator, they definitely won't trust yourself to emulate the simulator with the finger either. [1]: https://github.com/sstelfox/yubikey-simulator https://github.com/sstelfox/yubikey-simulator
- corndoge 6y ago> Before we go any further, I’d like to acknowledge the reasons for this. If a remote attacker were to compromise your laptop, being able to trigger the YubiKey from software on the computer defeats the whole point of using the YubiKey.
- dathinab 6y agoFor the new yubi keys with fido support I would recommend disabling OTP it massively improved the user experience for me., in difference to TOTP OTP has done fundamental problems. And fit reasons not affecting many people OTP is implemented by pretending to be a keyboard which is just anoying in many cases. But all other operation modes (FIDO,FIDO-U2F,PIV, OpenPGP) do not have that problem. So when possible I use password manager + FIDO(-U2F), where no it's password manager + TOTP using the yubikey (I plug the USB-c yubikey into my phone accessing the keys TOTP functionality through the authenticator app).
- girvo 6y agoI use U2F and TOTP, the latter through NFC via my iPhone or computer. U2F through NFC or USB. It’s great!
- thih9 6y ago> If you work in tech, you probably have a YubiKey I have worked in tech for 10+ years and I haven’t heard about this product until today. I guess it’s more likely to own a macbook/ dell / hp / etc than a yubikey. Still, if someone said “If you work in tech, you probably have a macbook”, they wouldn’t be taken seriously.
- pkz 6y ago"Now that we have that shell script, we can call it from other places as well. iTerm2 has a feature called Triggers, which can execute actions based on text matching a regex in your terminal. So we could write a regex to listen for “Yubikey for” and have it run the same script, eliminating the need to press buttons altogether." But isn't the whole idea that it shouldn't be possible to trigger it from software?
- peternicky 6y agoI’ve used various yubikeys in personal environments over the past 7 years and found them to be a gimmick rather than a useful tool. They are quite versatile and can be used for many different use cases which is part of the problem in my opinion. While not a total dummy, I found yubikey software and documentation to be difficult to use and configure and a pain to find how to setup the key for common scenarios. This brings me back to ideal users, probably corporate use where a dedicated team can support users for the specific use cases.
- xemute 6y ago"If you work in tech, you probably have a YubiKey". I stopped reading here.
- cja 6y agoSurely an authenticator app like Authy is more secure than a hardware key like Yubikey. To access my account with the former an attacker needs my phone and me to log in to it for them. To access my account with the latter an attacker just needs to hardware key. I usually have my phone on me whereas I don't want to have to keep track of a tiny USB device and am likely to just leave it plugged into my laptop. My laptop is the most valuable item in my home and so most likely to be stolen, along with the attached key.
- tjoff 6y agoDepends... Your phone runs millions of lines of code and you likely browse the web on it which means that any moment an exploit could take over your phone. (or the regularly scheduled bluetooth vulnerabilities). Bam, someone now have the ability to authenticate as you without even needing physical contact and without you ever noticing - this could run for years without any trace. With yubikey you will notice that it is missing. There is a yubikey with fingerprint sensor that is supposed to come soon as well. In my case, the biggest case against a phone app is that the most likely disruption would be either that my phone was stolen (though not specifically to get my credentials) or just break from a fall or something. And until there is a decent fallback from that passwords are the better choice for me. (Yubikeys aren't that much better in that regard either)
- psanford 6y ago> There is a yubikey with fingerprint sensor that is supposed to come soon as well It was announced 11 months ago with no status updates since then. Its really not clear that this product will ever get released.
- tialaramex 6y ago> Surely an authenticator app like Authy is more secure than a hardware key like Yubikey. It is difficult to assess one choices as "more" or "less" secure without a threat model. You've focused on the threat from attackers willing to use a mixture of a physical attack (stealing the phone or laptop, perhaps mugging you for it) and a digital attack (accessing online accounts using credentials they stole) but those are very rare. On the other hand Phishing and other purely online attacks are extremely common. I probably see two or three attempts per week. Most of them are crude but not all, and they work. Authy emits TOTP codes, so those can be phished. The phishing site gets you to enter your TOTP code, which it passes over to the genuine site, signing in the attacker with your 100% authentic working codes. But a Yubikey (and dozens of cheaper alternatives including Yubico's own Security Key) can also be used with WebAuthn, which cannot be phished.
- Melloww 6y agoWhy would one always leave the yubikey in their laptop? Isn't one of the security features supposed to be physical seperation of the key and the system when the owner isn't around?
- hda111 6y agoToo much untrue assumptions. I worked in tech for years and never used a YubiKey or similar device.
- homakov 6y agoNo, no one should own a yubikey. It's an entirely useless device. All you need is a pw manager that saves you from non-malware attacks (email compromise aside). Yubikey cannot save you from persistent malware, which makes it useless in almost all scenarios. The only hardware device that makes sense is the one with a screen (like trezor). Simple click-to-use devices carry no protections that you wouldn't otherwise get with a pw manager.