4 ms·
Yubikey is one - it requires the user touch a hardware device which signs something locally that I think is never sent? I don’t know enough of the implementatio
by fossuser 5y ago
Yubikey is one - it requires the user touch a hardware device which signs something locally that I think is never sent? I don’t know enough of the implementation specifics, but it’s supposed to guard against this kind of thing.
- klodolph 5y agoYubiKey uses U2F and FIDO2/WebAuthn. The YubiKey also does a lot of other things, depending on which YubiKey you have... but if you want 2FA on random websites, those are the most likely protocols (used for GitHub and the like). The basic U2F + FIDO2/WebAuthn is the least expensive model, around US$25. These days it works seamlessly on Chrome, Firefox, and Safari.
- laggyluke 5y agoYubikey is actually pretty "phishable", at least in the OTP mode. It will happily put the token into a phishing website (or literally anywhere else) as soon as you touch it. It's also good to know that Yubikey's OTP tokens don't expire based on time, but based on a hidden counter that gets incremented with every issued token. So if you've accidentally touched your Yubikey and leaked the token publicly, you just have to log out and then log back in using your Yubikey - that action will invalidate all tokens issued before this point.
- greggyb 5y agoYubikeys (or at least some models) can be configured with multiple different OTP implementations. Yubico's own OTP implementation behaves as you have described. It is not a guarantee that generating an OTP from a Yubikey means you have generated a Yubico OTP.
- 1024core 5y agoWhat happens if the Yubikey goes bad? I use one for work, and the last 2 keys I had developed some hardware issues, and stopped responding, so I had to get a new one.
- rob-olmos 5y agoThe recommendation is to have at least one backup key. There's also a WebAuthn extension in the works to at least make it easier to maintain a backup key by not having to pull it out of the safe every time you register MFA with a new service: https://www.yubico.com/blog/yubico-proposes-webauthn-protocol-extension-to-simplify-backup-security-keys/ https://www.yubico.com/blog/yubico-proposes-webauthn-protoco...
- shawnz 5y agoI really wish I could find a password manager which supports WebAuthn, and can also be unlocked with WebAuthn, so that only one secret needs to be replaced in such a situation.