6 ms·
Other than being a random untrusted USB device, is there any reason to not use the cheapest generic U2F device you can find? I've been wanting to start using t
by useryman 5y ago
Other than being a random untrusted USB device, is there any reason to not use the cheapest generic U2F device you can find?
I've been wanting to start using them for a while, but yubikeys are too expensive for me to get a bunch of.
- danieldk 5y agoI would try to find a key that supports ed25519, since there are concerns about the NIST curves used in ecdsa: https://git.libssh.org/projects/libssh.git/tree/doc/curve25519-sha256@libssh.org.txt#n4 https://git.libssh.org/projects/libssh.git/tree/doc/curve255...
- brnt 5y agoRemember that Github U2F key 6 years ago? It just supports the ecdsa keys... I feel a tiny bit grumpy that it took 6 years for me to be actually be able to use the thing for anything important and then to discover it's already outdated. I hope many services will support them nonetheless.
- darkblackcorner 5y agoI've Kickstarted Solo V2: https://www.kickstarter.com/projects/conorpatrick/solo-v2-safety-net-against-phishing https://www.kickstarter.com/projects/conorpatrick/solo-v2-sa... Still in production ATM but will support ed25519, and is open source
- comboy 5y agoWhat problem are you trying to solve? Yes you can get one for $10 instead of yubico's $20, but yubico's have been researched the most and importantly they are very reliable. Many people successfully abuse them and while you always should add a pair of them giving you a backup, it would be a pain if it would stop working. I'm asking because I'm curious about use case where you think you need them (even a bunch), but you think they are too expensive compared to value which you are trying to protect. Reliability would be a good enough reason to me even ignoring all security aspects.
- michaelt 5y ago1. Decide that USB C is a must-have feature. No $25 blue yubikey for you - prices now start at $50. 2. Decide you want two keys per user, in case they lose one. Now you're looking at spending $100+ per person.
- Aeolun 5y agoIs that an unreasonable expense for something like two factor SSH auth?
- Dylan16807 5y agoYes. And using a key like this isn't even two factor.
- selfhoster11 5y agoMost definitely. Not all people are made of money. $100 can buy a lot of things, so if I can't justify it for professional use, there's not much of an incentive to spend that much.
- spicybright 5y agoAssuming this is a business, you're already spending thousands per machine per user. And a developer that's down for half a day from a failed key is way more expensive than that $10 of savings.
- ptman 5y agohttps://solokeys.com/ https://solokeys.com/ ?
- skynet-9000 5y ago$25 USB-C: https://solokeys.com/products/solo-usb-c?variant=23528357560384 https://solokeys.com/products/solo-usb-c?variant=23528357560... For those not familiar, solokeys was an open source project that became a company via kickstarter (and now indiegogo)
- baybal2 5y agoSmartcards cost less than a dollar, and are omnipresent. I think you can already integrate PCSC with openssh. A good thing about smartcards is that ones compatible with CSP are driverless, and PnP in Windows. This means they can enjoy at least some semblance of keylogger protection for key password/pin with WinCAPI.
- VortexDream 5y agoGot any links about how to use a smartcard?
- rkeene2 5y agoStep 1 is to buy a reader, any reader which is ISO 7816 compliant is fine. Next, buy a smart card. The most famous brand I can think of right now is Gemalto, but there are lots of options. You can buy them in quantities of 1 extremely cheaply from AliExpress, but I'm not sure of the quality. Smartcards are just little computers which run Java Applets (GlobalCard), and they come either blank or with software already loaded on them. If they are blank you have to load software onto them. One open source option is CoolKey. In either case you will need software on your computer to talk to the software on the card to ask it to do things, like sign an arbitrary piece of data. This software is called middleware (the stack looks like Application -> Middleware -> PC/SC subsystem -> smartcard reader driver (usually CCID compliant) -> smartcard software, so why it's called middleware I don't know). For Windows, I only know for sure that PIV (US Government, NIST SP 800-73) card applets are supported, but there is a whole "minidriver" thing. I suspect you'll have to read the applet (or card, if preloaded) documentation to know for sure. macOS used to have a cryptographic layer called tokend, but it's deprecated and replaced with something else. For other things, PKCS#11 is the standard mechanism for talking to the card's application. Feel free to reach out with further questions.
- baybal2 5y agoExcellent write up on howto. A note from me, Windows also supports GIDS smartcards since a while too. Which means that Google titan key (Feitian ePass FIDO-NFC) will also work now (both as as smartcard, and a fido key.)
- tialaramex 5y agoYes, but, it's very unlikely that these reasons outweigh the benefits for you from having a Security Key. * Cheaper devices may not support cool new features. For example FIDO 2 allows resident credentials †. The cheapest behaviour for SSH is that your laptop (or whatever) stores some data, and you need that data plus the Security Key to authenticate to GitHub but with resident credentials that extra data can live on the USB Security Key and so that's a huge benefit if you git push from random PCs. There are several features like this - for example one way to replace that boot-up password on encrypted disks uses another optional feature of Security Keys - and there may be more in the future, the cheapest devices only have the core feature. But hey, if you discover you want those features you can always buy a fancier device later. * The cryptographic Quality of Implementation can matter. What we see today is some corner cutting maybe, some lack of polish, but nothing that seems like a plausible avenue of attack. But I haven't purchased every supposed different brand of Security Key, maybe some of them are quite awful. It seems likely that unless they're intentionally made to weaken your security they will always be much better than stuff like SMS 2FA. Here's a rather old post by Adam Langley about the crypto problems he found in various Security Keys: https://www.imperialviolet.org/2017/10/08/securitykeytest.html https://www.imperialviolet.org/2017/10/08/securitykeytest.ht... * The physical QoI can really vary. If you're buying the cheapest you can find, maybe the touch sensor or button wears out much faster than expected, or the USB connector is a tighter fit than you'd like. Or maybe not. Your mileage may vary a lot. I own a device with a ludicrously bright LED when its powered up, not just when authenticating, always if it has power. Doesn't bother me, but a lot of people would hate that. † Essentially without resident credentials the device has no "memory" of who you are. On web sites the natural back-and-forth makes this feel normal. You tell the site your email address or username, it finds one or more IDs in its database and asks your Security Key to authenticate with one of those IDs, the Security Key recognises an ID and does so. But a cheap Security Key can't remember that ID, it just knows (because of Authenticated Encryption if you care about the technical details) when it sees one it can authenticate. With SSH the protocol is designed differently, the remote site doesn't get an opportunity to store an ID and then ask your Security Key to authenticate, so that ID needs to live in a local disk file, unless you have resident credentials.
- Dylan16807 5y ago