3 ms·
to clarify: the biggest concern for these devices is that the prove of ownership is leaking. And an easy way would be to copy the device. Anything that copies
by treffer 5y ago
to clarify: the biggest concern for these devices is that the prove of ownership is leaking. And an easy way would be to copy the device.
Anything that copies the identity (private key) to a physical key is broken because the identity could be copied before it is on the key.
That's why you create a cryptographic keypair on the device, and the device does not offer to extract the private key.
It must be impossible to clone the key. When you read articles that claim 100% phishing failure due to these YubiKeys then that's because phishing is copying secrets. And you simply can't for the key. You have to physically steal this device.
And then there is also a human aspect. If you have something that is convenient and 100% successful then don't make it less convenient. You risk that people try to circumvent it.