6 ms·
It’s too bad the user experience across devices sucks. The best experience by far is a yubikey nano since it is mostly permanently attached to your laptop. It’s
by mdeeks 4y ago
It’s too bad the user experience across devices sucks. The best experience by far is a yubikey nano since it is mostly permanently attached to your laptop. It’s always there and you just quickly tap it. Love it.
Of course that doesn’t work with my iPhone. So I guess I need a second NFC yubikey that stays on my key chain in my pocket (which I don’t have since I don’t carry keys.). So then I have to remember to register both yubikeys. Then every time I have to login to GitHub or whatever on my phone I have to pull out my keychain (which I don’t have) and tap it on my phone.
I wonder when I can just get a virtual yubikey built into my phone. No extra device. My phone is my device. It kind of sounds like what Passkey is but I don’t want to pull out my phone to auth my laptop.
I really loved the idea and convenience trade off of SoftU2F. Too bad it’s dead now.
- tadfisher 4y agoAndroid has a built-in FIDO2/webauthn authenticator these days (well, built-in to Chrome, and by Android I mean Pixel phones). I'm sure Apple will build something similar as they have the hardware for it.
- acdha 4y agoHere’s Apple’s documentation from 2020: https://webkit.org/blog/11312/meet-face-id-and-touch-id-for-the-web/ https://webkit.org/blog/11312/meet-face-id-and-touch-id-for-...
- allset_ 4y agoThey called them Passkeys. It's FIDO2 with resident keys only AFAIK though https://developer.apple.com/passkeys/ https://developer.apple.com/passkeys/
- acdha 4y ago> I wonder when I can just get a virtual yubikey built into my phone. No extra device. My phone is my device. Last year, Apple shipped the first version of this: you can enroll your phone (or TouchID-equipped Mac) on sites like GitHub.com and it’ll use the Secure Enclave for WebAuthn secrets. I’ve been doing this since 15.4 came out and it’s great. Prior to that, I used a Yubikey 5 with USB and NFC, which is still handy since that’s where I store TOTP seeds for less secure sites. Passkeys extend that idea further by allowing you to register once and have it synced rather than having to register every device on every site[1]. That last part is important because AWS has a huge barrier: the number of MFA devices you get is one, which means you either need insecure things like synced TOTP seeds or you have to be comfortable never losing your Yubikey. I have been asking our TAM to prioritize fixing that for years so backups can be a real thing. 1. Over simplified a little - hear Adam Langley at https://securitycryptographywhatever.buzzsprout.com/1822302/11122508-passkeys-feat-adam-langley https://securitycryptographywhatever.buzzsprout.com/1822302/... for the right version
- judge2020 4y agoTo add, Chrome currently supports webauthn using your phone via BLE. When you try to enroll/sign in, if you click 'add an android device', that QR code will also work in the iOS camera app and allow you to use icloud to store & log in with that security key. The only real requirement here is a browser support and a desktop with bluetooth, something not super common on gaming / custom built PCs until a few years ago.
- acdha 4y agoApple did something similar: you can login using your phone’s WebAuthn credentials if you’re in BLE range. The main problem is that it’s Safari-only but the passkey spec should allow Firefox to implement it.
- mdeeks 4y agoTouchID unfortunately does not work with Firefox. Making it non viable for a large rollout. Yubikeys have the advantage of working with all browsers
- reissbaker 4y agoCorporate environments usually have no problem mandating a specific browser be used.
- saagarjha 4y agoRight, that's how we got IE6 :)
- staticassertion 4y agoRegarding AWS, it's truly insane that they only support 1 device (breaking from the FIDO2 recommendation) but you can also put AWS behind SSO, and then have 2FA on the SSO.
- Semaphor 4y ago
- lmm 4y ago> Of course that doesn’t work with my iPhone. So I guess I need a second NFC yubikey that stays on my key chain in my pocket (which I don’t have since I don’t carry keys.). So then I have to remember to register both yubikeys. Then every time I have to login to GitHub or whatever on my phone I have to pull out my keychain (which I don’t have) and tap it on my phone. That's why I use one of these rather than a yubikey: https://www.ftsafe.com/products/FIDO/NFC https://www.ftsafe.com/products/FIDO/NFC . I don't know why yubikey doesn't make a dual-method key when it's such an obviously nicer way to do things.
- vineyardmike 4y agoYukiKey does make a dual key. The problem is that these keys suck to have because you can’t leave them in your laptop and carry it around like that. Which makes it easy to forget. I personally was always forgetting my key when I worked in office. Or more likely I’d have the key and forget a USB A to USB C adapter (work was cheap and wouldn’t give out USBC keys). My new job gives out USBC keys and I have yet to forget it when I needed it. They just don’t work as NFC on a phone. https://www.yubico.com/product/yubikey-5ci/ https://www.yubico.com/product/yubikey-5ci/
- rolandog 4y agoRegarding the keychain issue, what works for me is using a wallet with a side pocket, that way the yubikey doesn't fall out... (can't remember the name for such an item; clutch wallet?).
- ghaff 4y ago>The best experience by far is a yubikey nano since it is mostly permanently attached to your laptop. Unfortunately ports are increasingly at a premium. You basically need to "mostly permanently" block the use of one of your USB ports for this to work. It's OK with my old MacBook Pro which has a USB port I mostly don't need to use for other purposes but thinner/lighter laptops don't have a lot of ports to spare.
- tkanarsky 4y agoIf you have a Linux PC with a TPM, you can use https://github.com/psanford/tpm-fido https://github.com/psanford/tpm-fido to create and "plug in" a virtual USB WebAuthn key whose secret is irretrievably stored in the machine's TPM. This effectively asserts that your specific machine is being used to enter a given site. However, it's important to remember it doesn't necessarily verify that *you're* present, or even if *anyone* is present at all, since the presence check is done via a software dialog and can be pwned along with the rest of the system.
- chromatin 4y agoAnd some sites like AWS management console don’t allow you to register more than one key :/