9 ms·
An Opinionated Yubikey Set-Up Guide
- XorNot 3y agoI feel like leaving the "backing up" section of this till last is burying an important part of realistic threat analysis here: i.e. the risk of losing access to data from losing, accidentally destroying, or a malfunction of your Yubikey is substantially higher then the risk of compromise. If you set all this up, then it would be an expected outcome that the most likely thing you'll be doing is needing to recover from a disaster, not prevent a compromise.
- deleted 3y ago[deleted]
- tomxor 3y agoI can't stress this enough, risk of losing (or breaking) your security keys is the number 1 threat when a service (correctly) offers no way to circumvent it's absence. This is the same for encryption: the number 1 threat is lost encryption keys; the number 2 threat is broken backups; the number 3 threat is stolen encryption keys. Having #1 occur is equivalent to being ransomwared with no way to pay. In both cases, you need multiple copies, or if you are using non-copyable aspects of security keys like U2F or OTP, then you need multiple backup keys registered to the same services.
- matthewtse 3y agoIt's for this reason that I eventually decided upon pencil+paper secrets in a bank safety deposit box, which can be backed up or even split up in a 2/3 fashion for things super critical. The yubikey ends up being solely for convenience for less important things(it's easier to press the yubikey physically than it is to bring out my google authenticator app and copy/paste a TOTP). Agreed that the article goes into extreme technical depth from a security/cryptographic perspective, whereas losing/breaking/being_stolen is actually the vastly more likely scenario.
- victor106 3y ago> It's for this reason that I eventually decided upon pencil+paper secrets in a bank safety deposit box This is not an option for the vast majority of people. But While we are at it, if the government wants to confiscate your bank locker they totally can and have access to all your secrets. So then what do you suggest?
- matthewtse 3y ago> This is not an option for the vast majority of people A bank SD box costs $50/year. Why is this not an option for a majority of people? If anything, it's more accessible to use a bank SD box than being a technical enough person to run code from a GitHub repo. > But While we are at it, if the government wants to confiscate your bank locker they totally can and have access to all your secrets. So then what do you suggest? The bank SD box isn't full proof (as any bank employee could take a peek), which is why you'd want to shard the secret into multiple SD boxes. I.e. if your secret is ABC, you could store three secrets of AC + AB + BC, wherein you need only 2/3 to recover the entire secret. This scheme is effectively the same as Shamir Secret Sharing, but way easier to recover. If your threat level is that the government might confiscate your bank locker, then you're probably at the level that you'd want geo-distributed sharded secrets in privacy-centric countries like Switzerland.
- victor106 3y agoThis is interesting, never heard of Bank SD box and the way you describe distributing the secret is novel. Do you have any links to a practical implementation?
- lxgr 3y agoThe government can totally take and use your Yubikey as well. Or often also just ask the service that you’re protecting a login for for your data directly.
- NoZebra120vClip 3y ago
- brantonb 3y ago> This is the same for encryption: the number 1 threat is lost encryption keys This is so true. I worked on v1 of BitLocker. Key management was a much bigger feature than the actual full-disk encryption. I only recently got a Yubikey because I know how easy it is to shoot myself in the foot, and I’m still very nervous about it.
- tw04 3y ago>or a malfunction of your Yubikey Can't stress this enough. I had a yubikey nano that I literally never pulled from my laptop, that sat on my desk for basically the entirety of COVID. It just up and died after about 14 months. Fortunately, I had only set it up for testing purposes because I was worried about this exact scenario, and while I had a backup in my safe, had I been on my normal travel schedule that wouldn't have helped much. The fact that it died after 0 abuse was a MAJOR turnoff for me ever proceeding down the path further. I'm sure my failure was a one-off but it left an extremely bad taste in my mouth. I get a failure of a key that's on a keychain or being beaten up on the regular, but failure from literally just sitting in a usb-c port for less than two years is... not a great look. I guess this might be an expected failure mode too, because their warranty is only 1 year for manufacturing defects.
- aborsy 3y agoYubikeys are well constructed. I don’t think they die frequently before several years.
- nixpulvis 3y agoOn the flipside, I’ve had a Yubikey 4C for around 4 or 5 years on my keychain in my pocket, and it’s holding up OK. Backup is a serious question though. I once started down this rabbit hole trying to type up a guide for using my yubikey and I found myself giving up when I realized there was no perfect solution.
- downrightmike 3y agoThink about it this way: forcing electrons through a circuit is abuse. Since they bumble around like flowing honey looking for the easiest way out.
- graton 3y agoI have Yubikey nano in my laptop, desktop, and Linux PC. All of them are still going strong. I have four Yubikeys on my keychain, two of which I bought in 2014, and they also are still working without issues. None of my keys have ever failed.
- matheusmoreira 3y agoAgreed. Turns out the best backup medium is paper: print out the secret bits and store them in a safe. The paperkey tool can do this and QR codes can make it really convenient. I even added binary decoding interfaces to zbar to support this exact use case. https://www.jabberwocky.com/software/paperkey/ https://www.jabberwocky.com/software/paperkey/ https://wiki.archlinux.org/title/Paperkey https://wiki.archlinux.org/title/Paperkey gpg --export-secret-key $KEY | paperkey --output-type raw | qrencode --8bit --output $KEY.png zbarcam --raw --oneshot -Sbinary | paperkey --pubring $KEY.gpg | gpg --import Not every key needs to be backed up. Signing keys are ephemeral, losing one is inconsequential. Losing an encryption key means it'll be impossible to decrypt data later so backups could be interesting. The master key should be kept permanently offline in a physical safe.
- lathiat 3y agoI have this same discussion about people using Vault and having secret unseal keys. If you're all in on the idea and have a robust process around key custody it's great, but if you just deploy it without thinking especially to an environment that may not be fully rebooted for 1-2 years at a time, it's far more likely someone will lose the keys and then only months or years later when the entire thing is restarted realise they lost all their data. And I'd put this as more likely than encryption at rest ever saving most people from data privacy. You have to include availability and user experience in your "threat model".
- dier 3y agoLike the other comments, the risk of losing data/access/etc is not enough. The article even actively suggesting you DO NOT make backups of things. Now you’re ready to generate a new set of OpenPGP keys on the YubiKey, using the generate command: gpg/card> generate Make off-card backup of encryption key? (Y/n) Enter n to ensure that the private keys never leave the YubiKey, and enter the admin PIN when prompted: I suppose this is why it's an Opinionated guide as my opinions on how the actual target of a "remote adversary" should go about balancing security with risk.
- aidenn0 3y agoYeah, if you're paranoid about the key being stolen when generated, just unplug the network, boot a live DVD image, store it directly to a USB stick, and then unplug the USB stick before rebooting. I usually don't go through quite so many steps, so if my machine was already actively compromised when I generated my keys, then the attacker has my keys.
- carbocation 3y agoI don't enable Yubikeys unless I can assign at least two to my account.
- chiefalchemist 3y agoIt's that simple. Yubi should just be a bit more transparent about the need for two or more.
- chiefalchemist 3y agoThe simple solution is to buy two, or more. Mind you, Yubi could be more upfront about the risk and the solution. But it's pretty obvious pretty quick that if your access depends on a single physical key that one key isn't enough.
- mixmastamyk 3y agoNeat, but this too hard I think. Have used a key with websites and that is doable for a regular (or busy) person. The rest of this should be done by the OS, through a wizard, at install time and/or later. Maybe a control panel app.
- jawns 3y agoI was gifted a Yubikey about a month ago, and I planned to use it as 2FA instead of having to open up Google Authenticator 10-20 times a day and copy 6-digit codes. It took a little effort to set up, but now it's working as intended. And I didn't realize it, but every time I had to pull out my phone and enter one of those stupid 6-digit codes, I was grinding my teeth! It was just such an annoying little chore. My mouth feels so much more relaxed now that I just tap the little button on the Yubikey. I also set up the long-press functionality to store a static password, and that has been the cherry on top.
- dtx1 3y agoSo... I just save my 2FA stuff in keepass... Works fine and can be backed up and replicated for free vs needing several yubikeys.
- sneak 3y agoThis works until you get malware on your workstation.
- anotherhue 3y agoOne can use the TPM so at least the secrets can't be mass exported. Doesn't stop keylogging individual ones of course (but a browser extension might).
- ics 3y agoThat’s why you assign all of them random names which are recorded in a separate BitWarden store. That one only opens with a password which is “YUBIKEY”.
- xwowsersx 3y agoI'm totally confused by the "backing up" section. > The best back-up is the buddy system: make sure at least one other person has an equivalent set of credentials for every application for which you use your YubiKey. Why is this the best option? How is it even a good idea at all? We're talking here about someone you deeply trust, I assume? I have a second Yubikey which is accepted everywhere my primary Yubikey is. Why is that the second-best option and not the best option? I must be missing something basic here. Can someone help me out?
- airtonix 3y ago[dead]
- aeternum 3y agoThe issue is something could happen to you and if your PIN is lost, it doesn't matter how many second Yubikeys you have. Seems like this advice assumes you're using your Yubikey to protect data you want to outlast you?
- xwowsersx 3y agoOh I see. Yeah that maybe applies to a small subset of the things I use my Yubikey for, but fair enough.
- sneak 3y agoThe author's idea that writing down your unlock codes and PINs on paper is an acceptable/reasonable backup system is, I think, a bit wishful, and quite impractical for most people. I recommend getting 5 Yubikeys, generating unique PGP keys on all of them, then storing two offsite in different locations, such as your vacation home or safe deposit box or office. Three are for your keychain and one each for your desktop and laptop or two laptops. Then, PGP encrypt your text file with all of these details to all five keys. I have two Yubikeys (a primary and a backup) in each of two safe deposit boxes in different states (4 total), one on my keychain, and one nano in each of my 5 computers. I encrypt my long term data to 10 recipient keys.
- tuatoru 3y agoEleven years ago I got four yubikeys, two pairs as recommended by Yubico. One pair for personal use and one for work. I tested the personal key pair first. The primary yubikey I had on my (physical) keyring failed spontaneously after less than three weeks of being carried around in my pocket. That was the end of that. I am not going back to physical tokens, except for RSA tokens and purely mechanical keys. Those have an adequate track record.
- codetrotter 3y agoI have four Yubikeys. One of them is a black one that work gave me for use with the work computer. I’ve had this Yubikey for over 1 year. Three of them are blue ones I bought from Amazon, that I also added to my SSO profile at work. I’ve had these Yubikeys for several months. One of them I keep in my wallet most of the time. One of them I keep on my desk and bring in my backpack when I go somewhere. One I keep in a box. One is somewhere in the room. I rotate between these, and I switch which one I keep in the wallet, which one I keep in a box etc. It’s worked well for me so far. None of them have failed yet, and when one does fail or get lost I will remain confident that the other ones I have will continue to work long enough that I can order even more Yubikeys to replace which ever ones went bad.
- tuatoru 3y ago
- Brajeshwar 3y agoWhat would be the ideal suggestion for a Yubikey setup -- where I’m not hounded by authorities, don’t want to act out the James Bond lifestyle, and am just an ordinary person interested in extra security for him and his family? I want to be able to have Yubikeys for (i) my primary desktop at home, (ii) my travel Laptop & other devices (iii) backup (at least two) if any of the primary ones fail. Rinse and repeat for each family member.
- Share6323 3y agoI need such a guide as well. If I want to sign up for a new service and use the yubikey as a factor is it required that I have all of them including the backup keys at hand to register them or can I keep them outside the house ?
- waynesonfire 3y agoUse the "FIDO (both U2F and FIDO2 flavors)" capability to protect your Gmail account. You don't want your email compromised.. it's the most important. Next, use 1password with the family. It too has FIDO support.
- hot_gril 3y agoMy suggestion for a regular person is to not deal with Yubikeys. The risk of me somehow shooting myself in the foot trying to use them is much higher than the risk of getting hacked. My most important thing by far is my bank account, which has 2FA via the Chase app on my phone. Doesn't even support Yubikeys. A few other things are like this. That's good enough for my personal life. I only use a key at work, where they manage all that for us.
- bigDinosaur 3y agoIf you travel overseas a Yubikey (or equivalent) is apparently a good way of escaping the account lockouts that Google applies when it detects suspicious behaviour. While TOTPs and regular passwords can travel a continent in a few milliseconds, a hardware key cannot, so anyone using it overseas is much more likely to be you. I've yet to test this but adding a hardware key is the advice I've found online around this particular issue. (Yes, I also have my own domain in the case I get fully locked out, I am paranoid)
- jwr 3y agoThe excellent guide by drduh should be mentioned here: https://github.com/drduh/YubiKey-Guide https://github.com/drduh/YubiKey-Guide — I've been using this approach for years to store my OpenPGP keys on Yubikeys and use them for SSH. I don't generate my keys on devices. That lets me be flexible and keep backups, as well as use the same keys on multiple physical devices. Using a single yubikey is a bad idea, as you're bound to eventually lose it or break it. Hasn't happened to me yet in 5 years, but I expect it to happen. I wish more sites supported hardware keys instead of only TOTP tokens, or (heaven forbid, but corporate idiocy is plentiful) SMS.
- wkat4242 3y agoI do generate them on device, I just have multiple Yubikeys. Of course there's a significant cost there, but OpenPGP cards are a good backup and cheaper.
- menthe 3y agoI've been using his guide forever as well, except that nowadays you can just use the native OpenSSH support for deriving Ed25519 or ECDSA keys from FIDO. The main advantage is that you do not have to deal with the very subpar GPG Agent anymore... https://www.maths.tcd.ie/~fionn/misc/fido_ssh/ https://www.maths.tcd.ie/~fionn/misc/fido_ssh/ Besides, 1Password now has a very convenient agent, which prompts users permission for an application to use a key - which is added security https://developer.1password.com/docs/ssh/get-started/#step-4-configure-your-ssh-or-git-client https://developer.1password.com/docs/ssh/get-started/#step-4... And yes, Yubikeys do break - My keychain'd 5Ci is missing a huge chunk of plastic, exposing the PCB, and among the two new C Bio I received last week, one has already fried after just a few days.
- bennyp101 3y agoYep, thats the same guide I used a few years ago as well! I use it daily for Github/ssh in general - and the 2 slots are used for part of passwords for a couple of other things. I have a couple that are used daily, one in a safety deposit box (which is the "master" key), and a stack of new ones on my desk in case anything breaks. (I used that Cloudflare offer to get a hefty discount on them). I also have a paperkey copy that lives elsewhere.
- karussell 3y agoWhat vendors for hardware keys would be recommended besides yubico? Isn't it a bit risky when there is mainly one (known) vendor for hardware keys? Or is this just the wrong impression that you get from HN?
- wkat4242 3y agoThere's no alternative with the same set of capabilities: Fido2, OpenPGP, PIV all in one. For the individual capabilities there's many alternatives.
- sufehmi 3y agoI was looking for a cheaper alternative than Yubikey etc - then I found token2. Their FIDO U2F costs only 5 euro. Now I can say to people I talked to that they no longer have any reason not to use security key. https://www.token2.com/shop/product/token2-t2u2f-security-usb-key-u2f-only https://www.token2.com/shop/product/token2-t2u2f-security-us...
- danpalmer 3y agoI feel like convenience is an important part of making security keys work effectively. These are definitely cheaper, but once you move out of the large bully USB-A keys to those that might not require adapters, might be smaller, more useful with things like NFC, they get a lot more expensive. Still cheaper than Yubikeys, but similar ballpark. I’m not sure this would change the maths on whether to use a security key or not for that many people?
- zoidb 3y agoMight also want to check out https://github.com/FiloSottile/yubikey-agent https://github.com/FiloSottile/yubikey-agent as a very simple way to setup a yubi-key as an ssh-agent.
- moreentropy 3y agoI would consider PIV and SSH through PIV/OpenPGP legacy and undesired nowadays. If you're only interested in state of the art second factor instead of passwords for sensitive use cases, a simple FIDO2 security key w/o all the extra features on a yubikey 5 is enough. You can solve most of those with only FIDO2 nowadays: Webauthn with fido/u2f is supported on most websites and oidc providers. SSH with FIDO and resident / non-resident keys is supported. PAM -> as documented in the guide, although setting origin and type manually isn't necessary and you can save keys in ~/.config/Yubico so non-root users can manage their keys. I would recommend enabling PIN verification with pamu2fcfg --pin-verification. LUKS hard disk encryption with FIDO2 for unlocking isn't covered but is possible, systemd-cryptenroll can set this up on modern linux distributions.
- dpeck 3y ago| Webauthn with fido/u2f is supported on most websites and oidc providers. I wish that was true. I’ve found that webauthn is becoming more common in the last year, but is still relatively rare. Many “important” sites and services make use of them. https://www.yubico.com/works-with-yubikey/catalog/ https://www.yubico.com/works-with-yubikey/catalog/ is a great place to see them, but they’re still quite rare as a whole.
- deleted 3y ago[deleted]
- 1letterunixname 3y agoNits: - Model: Ideal device is 5C. - GPG: S key should not also be C. The point is the C key should be the root of S, E, and A so they can be expired, revoked, and rolled individually. - NFC: Disable it or don't buy it. It's a wide attack surface. USB-C works with iPads and Android devices, iPhones <= 14 with an adapter, and iPhone >= 15. - Backup & recovery: Contrary to YK doc, there are too many issues with multiple card-generated YK secrets and identifiers for practical use. Create an identical device (apart from card no) with a 2nd YK kept offsite in secure physical storage by loading secrets to both rather than generating them on-card. It's possible to do so securely on a trusted machine (say running Tails or Qubes OS on a physical new machine without internet). - Reset PIN: It's foolish to not create one. - FIDO2: Setup your own (deprecated but still works) private, firewalled behind NAT server from https://developers.yubico.com/u2fval/ https://developers.yubico.com/u2fval/ - Linux and Mac workstations: Setup gpg-agent ssh-agent compatibility instead of the PIV method because it doesn't require their custom PKCS#11 module with an unproven security track record. And update the firmware with the Yubikey Manager app.
- nivenhuh 3y agoWhy is the adversary assumed to be female?