4 ms·
> I don’t see any use case or security benefits by using the static password feature. Even if you enter a password manually and concatenate it with the password
by vifon 4y ago
> I don’t see any use case or security benefits by using the static password feature. Even if you enter a password manually and concatenate it with the password of the Yubikey, a keylogger still gets both parts (assumption: You don’t reuse passwords).
If keylogger is what you're defending from, yes, it doesn't help. And in this scenario you've probably already lost.
On the other hand, it makes a large portion of the password immune to video-recording you typing the password in. Yes, it's technically trivial to then steal your Yubikey, extract the static password and combine it with the recorded one, but these are still quite some extra steps.
My point is, if a particular service or application doesn't support anything more refined, using a static password as a pepper[0] is perfectly fine and still an improvement over not doing so.
[0] https://en.wikipedia.org/wiki/Pepper_(cryptography) https://en.wikipedia.org/wiki/Pepper_(cryptography)
- atoav 4y agoAlso: something you don't know is also something you cannot tell the person threatening you with the 5$ wrench¹ ¹: https://xkcd.com/538/ https://xkcd.com/538/
- PaulWaldman 4y agoAren't you always vulnerable in this scenario? If you have your device in your possession, you also likely have your key in your possession in order to use your device.
- thesuitonym 4y agoIf your threat profile really includes the possibility of getting hit by a wrench, you can devise a means of destroying the key quickly.
- aYsY4dDQ2NrcNzA 4y agoMy YubiKey seems pretty rugged, which is why I feel okay carrying it on my (physical) keychain.
- bombcar 4y agoAlso if the wrench is a consideration, you really need to consider at what point you die rather than reveal. And note that you may die even if you want to reveal; especially if you've setup a system that prevents you from revealing (two person keys, etc).
- sargun 4y agoThe static password feature would actually be perfect with a few small alterations. I use Apple's Advanced Data Protection product. This product gives you a 64-character code you must know. I am probably not capable of committing this code to memory. I wish I could tell my Yubikey this code, and it would save it. --- Now, as a US citizen, it is very hard for the government to compel me to disclose a password or a pin code. If the static password feature required a simple password (say 6 characters), with reasonable brute force prevention, it'd make it so that I have a way to protect myself. On the other hand, if it is not pin protected, there is nothing preventing the government from getting a search warrant for the Yubikey itself and using that.