3 ms·
Could someone comment on how effective using a yubikey is at protecting companies? If they are good, I'm not sure why they aren't used more. I spoke to a gov co
by swframe2 5y ago
Could someone comment on how effective using a yubikey is at protecting companies? If they are good, I'm not sure why they aren't used more. I spoke to a gov computer friend and he said they would never use a yubikey.
- an_opabinia 5y agoIs it a significant improvement over a cellphone app like Authy? Not really. Then, sophisticated people need secure enclaves for signing, which are also ubiquitous via iPhones and not in Yubikey.
- senectus1 5y agoI'm in the mining space, one thing that I can tell you is that software in the mining and oil/gas space can be horribly archaic, poorly architecture and very poorly supported. I'm lucky for the most part in that my company is very cutting edge and running latest windows and pushing software devs/vendors to stay as up to date as us. But support for "new" tech like Yubikey authentication is very slow to encroach in these industries. Yeah I know Yubikey isn't new in the holistic sense. but its a lot "newer" than a lot of the tech in these industries.
- dyu 5y agoUS federal gov has their own PIV/CAC
- alert0 5y agoThey help against phishing and password theft, as it requires a physical item in addition to the password. Doesn't matter much if someone downloads a Word doc with macros and runs it.
- EricE 5y agotwo factor authentication can be enabled multiple ways - through dedicated hardware like Yubikey or via software via things like Google Authenticator or proprietary solutions like SecureAuth (around WAY before Google Auth). What 2 factor is used isn't important - what's important that you use some sort of 2nd factor (your password - something you know as being the first factor) that's limited to one physical device (something you have) that is not easily moveable. And NO, SMS is NOT 2 factor since you can bump a cell phone number from one phone to another pretty trivially with most cell phone companies (unfortunately). SMS is about on par with emailing you a code for secondary authentication. A barrier for a remote hacker who doesn't have physical access to you or your stuff, but not that high of a barrier.