5 ms·
I would gladly take an old stock yubikey at a discount - my threat model doesn't have a serious need for resistance to stolen keys, because at the user level th
by GauntletWizard 2y ago
I would gladly take an old stock yubikey at a discount - my threat model doesn't have a serious need for resistance to stolen keys, because at the user level they're unlikely to not notice them missing for long enough to successfully attack and then replace to a keychain.
- telgareith 2y agoYou're joking, right?
- mynameisvlad 2y agoThe vulnerability, as another commenter mentions, is extremely hard to exploit and requires both physical access and the specific accounts to clone the key for. That may be too much of a risk for enterprises, but as a personal security key? That seems like a completely reasonable choice to make.
- GauntletWizard 2y agoNo, I'm not. I've got a bunch of yubikeys locked in lockboxes when they're not in use, serving as trust anchors for internal PKI, but also using certificate logging. If one is compromised, there's a short window until it's known, and access to the box has a very small group of people. My threat model does not include "Insider under the watchful eye of two other insiders"
- wannacboatmovie 2y ago> My threat model does not include "Insider under the watchful eye of two other insiders" Some Mastodon infosec grifter is going to name this "Insider Triple Threat".
- deleted 2y ago[deleted]
- technion 2y agoA yubikey vulnerable to this attack perfectly protects against phishing, which is the attack the 99.9% of us have a practical reason to worry about. Not all vulnerabilities are equal.
- lxgr 2y agoBut so does a software password manager supporting passkeys – at a much lower price.
- deleted 2y ago[deleted]
- jyounker 2y agoBut lesser convenience and with more hassle.
- meowster 2y agoYou're right: a physical security key is a lesser convenience with more hassle than a personal password manager in my case.
- palata 2y agoBut a software password manager on a compromised computer can be compromised, right? It feels like the secrets can't be extracted by a compromised computer: the attacker needs physical access to the Yubikey. This sounds better than a software password manager, right? Or am I missing something?
- lxgr 2y agoDefinitely, but GP mentioned > [...] phishing, which is the attack the 99.9% of us have a practical reason to worry about [...] Both physical and software authenticators protect just fine against that.
- m-p-3 2y agoIf he understands the risks and deems those manageable according to their threat model, I don't see a problem.
- burnt-resistor 2y agoThe attack is local, limited, and requires sophistication to pull off. For most people and most use-cases, this is a theoretical vulnerability rather than a real one. While some users may need to buy updated YKs, perhaps having a tier of discounted "vulnerable" new old stock and more expensive patched new stock would make the most economic and utility sense.