42 ms·
I'm a bit confused by one thing, or why they don't mention it. Isn't TouchID on Macbooks already equivalent in security to a Yubikey? But this is another lay
by supernova87a 4y ago
I'm a bit confused by one thing, or why they don't mention it. Isn't TouchID on Macbooks already equivalent in security to a Yubikey? But this is another layer on top of that? (I guess you don't have a backup / alternate method for your MacBook touchID though, and that specific key isn't usable for other iOS devices)
- sebzim4500 4y agoI've never used TouchID, but I don't get how this could be true. You carry a Yubikey around on your key chain, so it's always in your pocket. Presumably you are not in the same room as your laptop 100% of the time.
- ezfe 4y agoNo, Touch ID is just a finger print reader. It can be used as a stand-in for a security key, but it's all in software on your device.
- WorldMaker 4y agoSome of it is also hardware: there's a trust module (Apple's preferred term is Secure Enclave hardware). That bit of hardware is directly comparable to a security key like a YubiKey: it stores secrets and keys in a way designed to make them hard to physically exfiltrate. Having something like Touch ID on a device is often an indicator that the device has a trust module (or Secure Enclave), though that isn't a guarantee. The Touch ID itself isn't generally considered a part of the trust module, but instead is often used as an ID to unlock keys in the trust module that have been locked to that biometric data. (Same generally applies to Face ID.) The biggest distinction between the trust module (Secure Enclave) in a modern device and a physical hardware security key is proximity. Obviously, a trust module is "right next door" inside the device itself. This has benefits (only need to carry one device) and detriments: lose the device and lose all the keys/secrets inside the trust module (protection from exfiltration includes protection from 'backups'); it's more complicated to use one device with the locked keys on another device (this is shifting somewhat today with new Bluetooth LTE-based personal area network "Passkey" standards) versus standalone hardware security keys are designed to communicate with multiple devices (often anything that supports some combination of USB or NFC); the threat models for accessing keys from a trust module if you have access to a device are different from the threat models for accessing keys from a hardware security key if you have access to only a device or only the key or sometimes even both. There's definitely cross-over between the hardware trust module on a modern device and hardware security key, but one is a dedicated device for it and the other is part of a larger device and has different threat models.