Show HN: A minimal web-based IMAP client for use on untrusted machines
github.com
github.com
Feedback welcome.
It's also quite annoying that you have to set up the keys beforehand. Though, obviously if you could connect to the server to create keys then you wouldn't need to use this. :/
Have you considered something like TOTP paired with Google Authenticator or the like instead of just the Yubikey for one-time passwords?
EDIT: I know you don't just use Yubikey. But, unless I'm not reading this correctly, the other tokens are pre-specified and can be exhausted.
HOTP might also be possible, but then you also have to store state (the counter) on the server side. Additionally that also seems to be limited to 6 digits in Google Authenticator.
My current approach is: Don't exhaust the tokens before you return from vacation :-)
I'm not familiar with Yubikeys other than that they exist. How're you using them for authentication? Do they not have the potential password reuse issue (seems they include TOTP support among other methods of authentication)?
Also, I'm fairly new to TOTP and was a bit surprised that Google Authenticator didn't allow for longer keys. That seems like it ought to be easy, to this layman, to implement for them.
===EDIT===
Found my answer to the Yubikey question. Read their documentation on how their OTP works. My initial confusion was based on a cursory read through where I saw they supported TOTP, but they have another method that's not time-based. So, yeah, not sure a good solution to the TOTP password reuse problem, but might spend more time looking into using Yubikey for myself.