3 ms·
> in what way is something like a yubikey secured via a password? It isn't, which makes me confused about how it is supposed to be more secure. If I lose my k
by jscholes 5y ago
> in what way is something like a yubikey secured via a password?
It isn't, which makes me confused about how it is supposed to be more secure. If I lose my keys with a physical security key attached, not only do I now have to worry about somebody breaking into my house, but all of my online/digital properties as well (assuming passwords become a thing of the past). If they have my phone which has Touch/Face ID enabled, that poses a much more significant challenge to an attacker (and can maybe be mitigated if I can remote wipe the device in time).
- staticassertion 5y agoWell, there is a pin on a yubikey[0], but I just meant I don't think it's totally necessary, and I'm not sure exactly when it's required. > but all of my online/digital properties as well (assuming passwords become a thing of the past) For sure, and that's definitely not a threat to take lightly - another thing to consider would be when the attacker is someone who inherently has physical access to you (say an abusive partner, parent, etc). You're totally right that a password can, at least to some extent, help in these situations. Like I said, I still see a use case for the password, it's just that the scope would change - like how password managers only require you to remember one single password, and that password is essentially only used in one place. This really reduces the risk of phishing. > If they have my phone which has Touch/Face ID enabled, that poses a much more significant challenge to an attacker (and can maybe be mitigated if I can remote wipe the device in time). Yeah, agreed - I think biometrics can definitely be a key part of how we get to a password-less world. There's other stuff too, like if the attacker has your key, but they're logging in from a new device, maybe it asks for some other verification like a biometric, or even a password / pin - but now the password again is taking a very different, much more limited role. All I'm really saying is that the current way things work is pretty bad. Passwords get forgotten, guessed, stolen, reused, phished, etc. Using a device solves those problems really well, and while it does have its caveats, I think the caveats are largely addressable. [0] https://developers.yubico.com/yubikey-piv-manager/PIN_and_Management_Key.html https://developers.yubico.com/yubikey-piv-manager/PIN_and_Ma...
- nightski 5y agoYubikey is amazing. I only use it on my really important accounts - financial, etc... So I generally don't need it on the road, it stays at home. I can use biometrics/sms for the less important stuff.
- GoMonad 5y agoWhich financial institutions use YubiKeys? I didn't think there were any. https://www.dongleauth.info/ https://www.dongleauth.info/ doesn't have any banks that do.