16 ms·
I've resisted switching to a hardware key because I know that I'm going to break it, and that seems like a huge pain in the ass. I really want to be able to mak
by throwaway52022 4y ago
I've resisted switching to a hardware key because I know that I'm going to break it, and that seems like a huge pain in the ass. I really want to be able to make a couple of backup keys, or maybe put another way, I want to be able to put the private key on the device myself, I don't necessarily care that the key is generated on the device and never leaves the device. I don't care if that slightly reduces my security - I'm not protecting nuclear weapons, my threat model is not state actors trying to attack me, my threat model is me leaving my key in my pants pocket before putting it in the washing machine.
- vngzs 4y agoYou just register 2-3 keys. It's not so bad.
- georgyo 4y agoIt's actually horrible! Even key rotation is horrible! My yubikey is getting to about 10 years old, and I have replacements for it but find it very difficult to switch. It will eventually fail as an things do and it will be problematic. The problem is that I have several dozen accounts connected to it and I don't know all of them. So either I'm carrying and trying multiple keys at all times or not getting into a site that haven't been rotated yet. Multiple keys on an all sites is also basically impossible. You need to register all the keys, and ideally those keys are in different places.
- bpye 4y agoI’m going to need to work this out soon. I picked up a pair of new YubiKey 5Cs yesterday with their sale. I’ve been using a YubiKey Neo for years for U2F, TOTP and GPG. Moving the GPG key is easy - though I might try using the FIDO2 support in SSH instead. However for every TOTP and U2F key I’m going to have to re-enroll the new keys… It feels like there should be a better way.
- bradstewart 4y agoIt would indeed be nice if you could "cross sign", CA style, a new yubikey with an old one, and that would somehow get passed along to the various services. I have not thought about the various attack vectors that this may or may not enable though.
- andrey_utkin 4y agoI've recently started to track my service dependency graph! So like, to keep using github I need my password store, my email and one of my two security keys. To use my email, I need... Please contact me if you're interested, I will release the tooling I have.
- _vdpp 4y agoFIDO2 with resident SSH ed25519 keys works great, just make sure the OpenSSH client and server versions on all the machines you’ll be using the key on support it. I wish there was a way to sign Git commits somehow using them instead of PGP.
- jameswryan 4y agoThere is as of Git 2.34 [0][1]. [0] https://github.blog/2021-11-15-highlights-from-git-2-34/#tidbits https://github.blog/2021-11-15-highlights-from-git-2-34/#tid... [1] https://git-scm.com/docs/git-config#Documentation/git-config.txt-gpgprogram https://git-scm.com/docs/git-config#Documentation/git-config...
- _vdpp 4y agoOh nice! No more futzing around with GPG. You just made my day.
- lrvick 4y agoYou can backup/restore FIDO2 keys via BIP39 on supported devices like a Ledger or Trezor.
- eMGm4D0zgUAVXc7 4y agoDo you only have 2-3 backups of your workstation? I have much more backups of my workstation etc., should I now buy dozens of crypto hardware key thingies and constantly switch them around to match the backup disks? For those who do offsite backups: Is an offsite backup possible across the Internet? Or do you have to physically drive the key to the offsite location? When I create a new account somewhere, does that mean I have to move N backup keys out of their drawer to the workstation and register each of them on the account? And how to even create a backup and keep it in sync? With backup disks, it is a matter of shutting down the machine, removing one disk from the RAID1, and you have a backup (the removed disk is the backup). Or doing "dd if=..." if you don't use raid. Is something as simple possible with those fancy crypto toys? Or is some arcane magic required to copy them? Is this perhaps all as usual: An attempt to get more control and tracking of users, disguised as "security"?
- lrvick 4y agoWith devices that support BIP39 backups like the Ledger or Trezor, you are backing up the random seed that generates all possible future accounts deterministically. Backup once, setup 100 accounts, lose authentication device, restore backup to new device, regain access to all 100 accounts. Easy.
- throwaway52022 4y agoI keep an off-site backup at my parents house. Right now it includes a printed copy of my backup codes, so if my house burns down and everything is a total loss here, I at least don't have to start from zero. They live far enough away that my backup offsite backup can get to be a few months out of date but that's usually fine. (If I were to make a major change in something I'd make a special visit) I don't want to spend a bunch of time when I visit to find that key and add it to all of my new accounts and hope I got everything - I want to make a backup of my current key right before I visit and when I visit, I just put the new backup key in the desk drawer and take the old one home with me.
- lrvick 4y agoUse a Ledger or Trezor which supports backing up the random seed allowing you to backup all current and future accounts in one shot.
- michaelt 4y agoEh, retrieving a key from off-site storage every time you open a new account is a pretty big inconvenience, even for a security enthusiast.
- lrvick 4y agoYou can use devices like Ledger that support BIP39 backup allowing you to create duplicate devices any time from a 24 word random seed. Now your one time backup covers all current and future services.
- blep_ 4y agoYou've recommended "devices like Ledger" many times in this thread. Are there things that support this that aren't cryptocurrency wallets?
- lrvick 4y agoPeople have made the same incorrect assumption that fido can't be backed up many times and it is a common misconception that halts adoption of the best security win since TLS. I feel important to correct this in tech circles so we start telling friends and family to setup a solution to the most common account loss problems. Also, BIP39, the only backup spec that exists for FIDO atm, originated in the Bitcoin community where key loss is a very expensive problem that needed an elegant solution. BIP39 can be used to backup any type of asymmetric cryptographic key that could ever exist in a human friendly way but sadly I am not aware of any vendors implementing it outside of hardware wallets which are general purpose tools They can be used for PGP and FIDO and password management without using them for cryptocurrency and this is totally valid.
- blep_ 4y agoI absolutely agree that this is a thing that needs to be solved. I cobbled together my own solution using undocumented bits of the Solo firmware[1], but that's not nearly usable enough for average users. But here's the problem: outside of the hype bubbles, cryptocurrency stuff does not have a good reputation. If the only thing that supports this markets itself as a cryptocurrency wallet, that is going to hurt adoption. People generally do not buy devices in which they actively do not want the main feature. (I did remind myself of DiceKeys[2] while looking through my notes to find [1], but that has its own problems, such as "oh god what are you doing why does this involve OCRing a photograph of dice on my phone".) [1] https://github.com/solokeys/solo1/blob/4.1.5/fido2/ctaphid.c#L784 https://github.com/solokeys/solo1/blob/4.1.5/fido2/ctaphid.c... [2] https://dicekeys.com/ https://dicekeys.com/
- beefee 4y agoThe services I interact with that support WebAuthn usually only allow you to register one key. Backup and recovery is a confusing puzzle for most of these services.
- Hamuko 4y agoTell the services you interact with that they're basically going against the spec. "Relying Parties SHOULD allow and encourage users to register multiple credentials to the same account. Relying Parties SHOULD make use of the excludeCredentials and user.id options to ensure that these different credentials are bound to different authenticators."
- 2OEH8eoCRo0 4y agoIs it a SHOULD vs SHALL issue? Link to full spec?
- Hamuko 4y agoIt's SHOULD as per RFC2119, so basically you need to have a good reason with an understanding of the implications to ignore it. One of the implications here being that you have zero available authenticators if your main authenticator breaks. https://www.w3.org/TR/webauthn-2/ https://www.w3.org/TR/webauthn-2/
- rootusrootus 4y agoI haven't run into any like that, but I'm with you -- if I could only store one webauthn key, I wouldn't use it at all. Too risky.
- dividedbyzero 4y agoI believe AWS root accounts don't support more than one key to be added.
- droopyEyelids 4y ago
- graton 4y agoThat's what I do. I have a nano Yubikey installed in each of my computers. Plus a Yubikey on my keychain. I register all of them with each account. All of the accounts require username / passowrd and the Yubikey. I'm not willing to not have a password.
- RandomChance 4y agoI think this is the best approach, the one mobile key allows you to add your other devices as you use them so it's not adding a ton of overhead.
- browningstreet 4y agoSo if you're travelling overseas for 3-4 weeks, you need to keep extras in all your different luggage/bags, just in case?
- xdennis 4y agoWhy do people always say this? Do you not know how expensive they are?
- lrvick 4y agoMost people have smartphones which ship with WebAuthn so they are good to go. Granted phones are like $500+ so by contrast a Yubikey is a much cheaper alternative for a secondary backup device for most people.
- eswat 4y agoAWS has entered the chat.
- vlan0 4y ago>my threat model is me leaving my key in my pants pocket before putting it in the washing machine. "YubiKey Survives Ten Weeks in a Washing Machine" I think you'll be safe! :) https://www.yubico.com/press-releases/yubikey-survives-ten-weeks-in-a-washing-machine/ https://www.yubico.com/press-releases/yubikey-survives-ten-w...
- eMGm4D0zgUAVXc7 4y agoSource: The people who sell YubiKeys.
- john567 4y agoI was about to say the same thing. These things are quite sturdy and if you loose your key (as people do) you retire the old one and make a new. These things are neither expensive nor irreplaceable. Of course if you loose your key it's going to hurt, as it should. I've had a Yubi Key for almost 5 years now. Zero issues.
- lxgr 4y agoWhile I'm generally a fan of YubiKeys too, I've had one break without warning. Backups are highly recommended – you can lose them too, after all.
- Kelteseth 4y agoI wanted to enable YubiKey for my Bitwarden account and feared exactly this. Now I've spent 200€ for 4 YubiKeys, so if I ever miss or break one, I will hopefully be fine. But imagine telling your grandma to buy at least 2 YubiKeys for 100€ just to make your Facebook login more secure.
- deleted 4y ago[deleted]
- xur17 4y agoHas anyone tried a Ledger or Trezor device for something like this? Your FIDO U2F private key is deterministically generated [0] based upon your seed phrase, which you can backup, and restore on other devices. [0] https://www.reddit.com/r/ledgerwallet/comments/udzx1c/ledger_fido_u2f_app/ https://www.reddit.com/r/ledgerwallet/comments/udzx1c/ledger...
- aaaaaaaaata 4y agoAny input which (Trezor/Ledger) is least likely to be a honeypot?, and/or a good device?
- xur17 4y agoWhat do you mean by a honeypot? Both are pretty well trusted devices, and users easily have tens of billions of dollars deposited on them. Given that, I feel pretty comfortable using them for 2fa.
- lxgr 4y agoAt least Ledger actually does support U2F as an installable application, but that's the predecessor to FIDO and has some weaknesses in comparison. I'm also not sure whether WebAuthN supports legacy U2F authenticators without the browser performing some protocol translation.
- nybble41 4y agoLedger and Trezor both support U2F, which is a FIDO protocol but not the latest version. The Trezor Model T additionally supports FIDO2 (WebAuthn).
- eswat 4y agoI have a Ledger as a backup key. Keyword is backup since it's less convenient to use than a Yubikey due to needing to put in a pincode first. Though that could be a security feature in and of itself.
- md_ 4y agoThis announcement is primarily not about hardware keys, right?
- adam-p 4y agoI killed a Yubikey in my pocket (without washing) after four years. Get two and keep the backup safe. https://adam-p.ca/blog/2021/06/backup-yubikey/ https://adam-p.ca/blog/2021/06/backup-yubikey/
- lrvick 4y agoI have abused and soaked every model of Yubikey. I even melted the casings off every model with acetone to lookup chip specs and Yubico responded by switching to a new unidentified glass hybrid compound no common solvents seem to impact. In all cases the Yubikeys still worked even as bare abused PCBs. You need a blowtorch or a drill to break one.
- db65edfc7996 4y agoHear hear. I already have enough to worry about besides this little magical security wand failing/getting lost. I require a bullet proof method-of-last-resort mechanism in place for the inevitable day when the fob is no longer available.
- raxxorraxor 4y agoI want to have both, a hardware key and a password. A password alone always has to grant me access again, ideally without needing to register a machine too. Honestly I hate that this is so widespread already, I want my devices to be a non-recognizable ghosts for security purposes. An access log would be more appreciated. I have a Yubikey and use it as a part of my passwords. But I would like to have a second master password that I only use in emergencies. Yes, it is easy to forget so make sure you don't. But a password that is rarely used is also rarely exposed to third parties. To be honest, the most problems I see with FIDO is the lacking trust in the alliance of companies behind it but I don't know too much about the technicalities of FIDO.