4 ms·
An AES key is symmetric. Both parties need it for this cryptographic operation. The OTP key is separate from other keys that enable WebAuthn. Also, please don
by cendyne 3y ago
An AES key is symmetric. Both parties need it for this cryptographic operation.
The OTP key is separate from other keys that enable WebAuthn.
Also, please don't use Yubikey OTPs. While they can't be brute forced like TOTPs, they can be phished. There are better technologies to implement.
- antonjs 3y agoAs someone shopping for physical 2FA tokens right now, do you have any recommendations?
- stouset 3y agoYubiKeys. Just use FIDO2. I have no idea why OP is trying to use the YubiKey OTP protocol, which is legacy.
- jadamson 3y agoI wasn't trying to use it, I was just looking around and came across the "YubiKey Personalization Tool", which doesn't show anything about FIDO2. Now that FIDO2 has been mentioned as something that solves this issue, it turns out there's another tool called the "YubiKey Manager", which allows you to configure/toggle various "applications" on a key, including Yubico OTP and FIDO2.
- meepmorp 3y agoYubiKeys are fine, just avoid their proprietary OTP thing. They're fairly configurable and also do FIDO/WebAuthn, as well as TOTP/HOTP, PGPcard and PIV.
- slim 3y agonitrokey
- Alex63 3y agoI like my OnlyKey.
- aborsy 3y agoMy understanding is that, TOTP are equally vulnerable to phishing. Hetzner Cloud and Bitwarden use Yubico OTP.
- sneak 3y agoUse U2F instead.
- m-p-3 3y agoU2F is FIDO1 though, everyone is switching to FIDO2/WebAuthn/Passkeys.
- advisedwang 3y agoTOTP can be phished. The parent is recommending FIDO/WebAuthn
- vel0city 3y agoI don't think I've ever heard of people actually brute forcing TOTPs on any halfway decent implementation. Since they rotate every so often you'd have to hit the whole range of 000-000 to 999-999 in like 15 seconds. A simple rate limit of only allowing a few tries every 30 seconds would completely prevent TOTP brute forcing while still being plenty accessible.