3 ms·
I think you have the wrong perception on how YubiKeys add to your security. 2fa means you use different proves. A password is proof that you know a secret. A Y
by treffer 5y ago
I think you have the wrong perception on how YubiKeys add to your security.
2fa means you use different proves. A password is proof that you know a secret. A YubiKeys outputs proof that you are in possession of this device. The tapping is there to avoid rootkit based exploits (e.g. streaming the data to another device on demand).
Adding a password to you YubiKeys does not add anything to this. It does not strengthen this.
- treffer 5y agoto clarify: the biggest concern for these devices is that the prove of ownership is leaking. And an easy way would be to copy the device. Anything that copies the identity (private key) to a physical key is broken because the identity could be copied before it is on the key. That's why you create a cryptographic keypair on the device, and the device does not offer to extract the private key. It must be impossible to clone the key. When you read articles that claim 100% phishing failure due to these YubiKeys then that's because phishing is copying secrets. And you simply can't for the key. You have to physically steal this device. And then there is also a human aspect. If you have something that is convenient and 100% successful then don't make it less convenient. You risk that people try to circumvent it.
- jl2718 5y agoI like to think of passwords as proof that you’ve exposed your secret.