Yubikey with USB-C
yubico.com
yubico.com
https://github.com/Yubico/ykneo-openpgp/issues/2#issuecommen...
Edit: Never mind, there's actually a reasonable explanation for the change: https://www.yubico.com/2016/05/secure-hardware-vs-open-sourc...
https://news.ycombinator.com/item?id=11691655
It is interesting how it allowed revealing the details of a bug in the implementation, though.
https://developers.yubico.com/ykneo-openpgp/SecurityAdvisory...
It's significantly better than completely closed though!
It's like a parachute that almost opens.
I guess it's really hard to fit all of the electronics in a port as small as USB-C though.
It's acceptable if you only use it for OTP, but I can't get myself to put GPG private keys on a Yubikey Nano...
There are DPA attacks to be worried about, but if you set a decent PIN and limit the number of failed attempts your GPG keys will probably be safe if your Yubikey is ever lost/stolen.
I'd hate to not be able to use the USB-C Yubikey with my desktop, my keyboard port, my hubs, etc. Seems easier to just use the normal Yubikey plus a dongle for the few machines that support USB-C.
That doesn't mean they don't exist - you can find a few on Amazon - but reputable companies aren't making them, so quality is going to be suspect.
Are you military personnel who is in charge of turning the key and launching the nukes? -Excellent reason to have a key that is impossible to forge. -Also, "key discipline" is likely very high.
Are you a paranoid nerd that wants to make sure that you cannot be compromised? -Excellent reason to have a key that is impossible to forge. -But what happens when you lose that security token?
i.e. "Honey! I can't find the car keys, have you seen them?"
We desperately need _BETTER_ 2FA. Bio-metrics are not the answer. I would be in favor of an implantable RFID chip or whatever 'better' tech comes around.
Pretty simple: you use your backup key to revoke the lost key. This is possible with e.g. Lastpass and Google. Of course, if the attacker logs in before you revoke the key, you are hosed, but the same would be true in your car analogy.
> i.e. "Honey! I can't find the car keys, have you seen them?"
With car keys, too, you have a backup key. Arguably, the physical car keys are easier to copy.
> I would be in favor of an implantable RFID chip or whatever 'better' tech comes around.
Nothing new, see this article from 2004 [1]. As you can read in the article, its first headline was even in 2001 (to put in perspective this is 15 to 16 years ago). Company's name is VeriChip.
The problem is that the signal can be intercepted (AFAIK it doesn't use a form of OTP), and the key cannot be easily replaced/revoked. A YubiKey doesn't suffer from this issue. The issue a YubiKey has is that it can be easier lost than an implant.
The YubiKey Neo ('large' version, not the 'laptop' version) supports NFC.
> We desperately need _BETTER_ 2FA.
Why? How?
What if you lose the backup key to your car? You're can break a window to enter, but a modern car won't start easily because of the lock on the steering wheel.
Make sure you don't store both keys at the same place. Make sure one is stored at a secure place, while the other one is securely attached with you. A secure place to store a key is a fireproof safe, or a notary.
Can you do the same with crypto?
The procedures to maintain access to your car aren't really sufficient.
If you're afraid you lose both your main key as well as your backup key at the same time before you were able to reinstall another backup key you can ensure you have more than 1 backup key, and/or (re)consider where you store your backup key(s).
Also, it depends on where you are using the YubiKey. If its an online service you may be able to identify yourself via alternative ways. If its your FDE, you're hosed. Or you have backups. Either way, the above still applies.
That exactly what the FIDO protocols are trying to do.
You can use you shitty local fingerprint sensor as a authenticator but you will still get better security agains everything exept if somebody steals your phone.
Phising is the biggest problem, it needs to be solved. We can do it in the first or the second factor. People either need to move to U2F or they need to move UAF on the first factor.
This is really the only hope.
Biometrics are a way to identify a user (and establish a username); not a form of authentication or replacement for a password. This is because biometrics cannot be replacement, while they can be copied or mimicked.
1FA is theoretically possible without a password, with a form of OTP.
As do [secure] passwords. Which I'll demonstrate below.
> My finger prints are rarely intact enough for a fingerprint reader to capture them and read them.
Scan multiple fingers. Use different biometrics such as a photo of your face, or your eye. Remember, biometrics are meant as username replacement, not authentication (e.g. password-based); ie. so you don't have to type 'lightedman', not 'ethically-rage-retake-unlined-wrangle-lapel'.
http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...
Tell that to my fiance's iPhone, or my HP NX-series laptop which has Windows XP and a biometric user authentication login, I don't think they got the memo.
"Scan multiple fingers"
I guess you didn't read what I wrote. I'll just stop here until you do.
Sadly, they haven't. Did you get the memo where people from CCC got the fingerprint from a minister, just to prove a point?
> I guess you didn't read what I wrote. I'll just stop here until you do.
I did read what you wrote. That doesn't refute that in use cases, one finger(print) may stop working while another still works. It also doesn't refute that other biometric data stays intact. Although having to type 'lightedman' is a minor nuisance.
And they could have got his phone PIN just by standing in line behind him at Starbucks when he unlocks his phone
Not in mine. Simply put there are too many cuts on every single finger on my hands to make biometric fingerprinting a reliable thing, and those cuts change pretty much daily. Do mining like I do, in hard rock, with hand tools and no gloves (because you need to feel for things lest you destroy a perfect specimen.) You're not escaping uncut, no matter what.
For people like you we either need alternative way of identification (such as face recognition), or we need you to type your username ('lightedman'). The latter is IMO (in 2017, without physical keyboards) rather annoying.
Remember, I don't suggest we authenticate via fingerprints.
Using Biometrics for claimed identity is a choice (I guess...it's not one I've heard of before), not a mandate. 2FA doesn't specify what factors line up with with "claimed identity" vs "confirmed identity" - just that 2 factors is more secure than 1 factor.
I've never heard of "used biometrics as username, and a password as password", nor that "biometrics are meant as username replacement". Have I fallen behind, or am I misunderstanding you?
My understanding is that, in CONFIRMING identity, you want at least two of "know something, have something, be something". Every example I've heard/seen (admittedly limited) used these to confirm a claimed identity, not to make the claim in the first place.
I think that's a solution in search of a problem. That may be all biometrics are actually good for; I don't think it's why anyone is interested in them.
It's really not that big of a problem, at least in the "paranoid nerd" context. Just have backup keys that your users can print out and keep in a safe place. Or have more than one U2F device - most implementations I'm aware of allow users to register more than one device.
Of course, for most applications, there'd still be the usual support backdoor. That's definitely a problem not quite as easy to solve.
Moreover, U2F already is awesome 2FA (better than _BETTER_). Fast and unphishable. Buy a few of these, keep one on your keychain, one on your desk at home, and a backup locked in your safe, and you're all set.
We use the USB-A version of these things extensively at my company, and they're unbelievably convenient.
Like a vivokey? http://vivokey.com/learn-more.html
Seems like the main reason is so that the guy who made it can call himself a transhumanist and say futuristic things.
Watch him put his phone to his wrist. If it was on his finger he wouldn't have to take the phone out of his hand. Is that thing glass? How is he not worried about it shattering when he falls?
I found http://nfcring.com/ but macbooks can't do NFC, otherwise I'd preordered one.
I also learned that NFC is RFID at 13.56 MHz.
Notably, it's the first NFC 4096 bit capable device I've seen (Yubikey Neo is max 2048bit; Yubikey 4 doesn't have NFC).
The only downsides are: one fewer USB port, and the green light on the yubikey which is permanently lit.
The advantage of a Yubikey over a TPM in this case is that the Yubikey requires a physical tap before it'll sign a request, which prevents certain MITM attacks.
The yubikey is one factor, the VPN also requires a second factor (memorized password). These are concatenated so you type the password without pressing the enter key, then tap the yubikey (which "types" the OTP + enter key). This process works in web forms, shells, etc. Could hardly be simpler.
If the laptop is lost/stolen, I can deactivate the token.
I have multiple desktops, laptop and several mobile devices that I often context switch across. I'd like to use 2FA without having to plug and unplug the key every time I want to switch devices.
(This assumes that you're OK allowing physical access to the device to count as one of the factors in 2FA, instead of e.g. physical access to your keychain or wallet or messenger bag where you would otherwise keep the key.)
But I have one long password (30 characters) for logins and disk encryption, and everything else is 1Password/2FA. If you allow cookies, you won't get asked to use the key again. Most sites allow you to also use an authenticator app on your phone (some even force you to also set this up when you add a key). And I have GPG subkeys for every machine, so the key is only needed for the initial bootstrap. So this way, the amount of times you actually have to use the key is low. I'd say I use mine one a week, maybe less.
Which is a good idea if your key gets crushed.
Too bad a lot of phones don't have NFC, or the NFC doesn't work with the YubiKey Neo.
Given it is wireless, is it eavesdroppable?
"Your YubiKey provides a second factor of security for your logins, beyond a username and password. Your YubiKey needs to be registered or paired with each computer, service, or site you use it with. "
I believe this adds protection against phishing because the browser communicates which origin (that is, which domain name) is sending the challenge, and that gets hashed into the signed response. So if trust-me-im-google.com proxies google.com, it can ask you for a one-time password, and the one-time password will be valid when google.com gets it, so the MITM can get your login cookie. But if you're using U2F, the signed response will say "Yes, I would like to authenticate to trust-me-im-google.com", and google.com will reject that.
[1] describes the flow at a high level, and [2] goes into more details
[1]: https://www.yubico.com/about/background/fido/
[2]: https://developers.yubico.com/U2F/Protocol_details/Overview....
https://developers.yubico.com/U2F/
Yubico has some python code here:
https://github.com/Yubico/python-u2flib-host
https://github.com/Yubico/python-u2flib-server
Chrome builds U2F into the browser itself for website authentication.
Another choice that looks (sadly, for me) more popular: https://github.com/ashtuchkin/u2f
I do like the idea of being able to plug in to authenticate for ssh on any computer, however...
I genuinely want to understand this so I'm hoping you or someone else can explain.
Yubikey's and the like are a high target item, but probably only for government-level adversaries, in general you have to be pretty well funded to attack these things, plus their attack surface is very very small, and most all of the attack surface is physical (i.e. you have to physically get the yubikey device to attempt any hacks on it). These devices generally only have a USB port, so to get at them remotely you have to first get remote access to the device(computer) they are plugged into, making it even harder of a target.
That's the general overview. Specifically, SMS received tokens are not secure (because of the SMS part not being secure). NIST recently declared SMS based 2FA to be a bad idea, for instance.
If someone can remotely root your phone, they can remotely retrieve your shared secret, and thus generate your authentication tokens.
The only thing TOTP protects against is somebody collecting logins and using them later. Today good phishers do attacks JIT, so TOTP is pretty useless for that attack vector (and that is the most importent one).
Your Yubikey can pretty much be connected to your computer all the time. So usability is actually better.
Plus there is of course the problem of smartphone security.
https://www.wired.com/2016/06/hey-stop-using-texts-two-facto...
Other comments expalain the vulnerbility of phones, but Linode's Time-based One-time Password implementation (tied to a phone app) may have been hacked server-side.
http://www.securityweek.com/how-attackers-likely-bypassed-li...
- Clicking button is far easier and faster (it really does make a difference).
- Your smartphone is complex software and often attacked. Secrets can be stolen.
- Based on public-key crypto, no secret on the server.
- Built in phishing protection
- Your own private key is secure hardware that you can't read the key from
To be fair, a smartphone could also implement U2F and you would get some of the same benefits. Samsung phones for example already support UAF (the other FIDO) protocol.
It's not really possible to verify randomness this way - particularly for a device that already has a decent chunk of storage and crypto operahtions. Suppose the "random" number generator is actually an AES keystream coming from a key controlled by the NSA - how would you tell?
A yubikey 4 or Neo has 2 slots which can be configured for about 5 different things. OTP, challenge response, static password, and some other things I can't remember right now. It also has 3 slots for a PGP private key, signing key, and encryption key. It also has 4 PIV slots to use as smart card key storage for authentication (ssh), code signing, and other things I can't remember. Then there are additional PIV slots to hold expired keys you might want to keep around for some reason?
It has quite a lot of functionality for a little device. The main difference between Neo and 4 is Neo has NFC, where 4 supports 4096 pgp keys. 4 is the newer one, but nothing new has NFC yet.
I use it with luks for full disk encryption, ssh, and to store my pgp key for QTPass/Android Password Store. QTPass + passff extension for firefox is nice.
I haven't set it up as a 2FA for sudo yet, but that's possible also. I don't plan to use it for PGP encrypted email for the same reasons described here.
Everyone of us has asked that question before :)
Open to contributions as well!
It's definitely not that ground breaking but it works, provides reasonable extra security and meets my requirements. It lacks some of the feature of Yubikey like storing GPG on there or HMAC etc, but I don't need those functions in reality.
[1] https://freeotp.github.io/ [2] https://github.com/google/google-authenticator-libpam
Currently my YubiKey Neo only supports RSA 2048 as it's a hardware limitation of the NXP A700x chip used inside.
[0] https://www.yubico.com/2015/02/big-debate-2048-4096-yubicos-...
The yubikey also supports PIV. There you still can only use 2048.
But its really all the fault of apple stupid NFC police, not some other issue.
(Long time no chat btw!)
(Jeremy, is that you? Long time indeed!)
Their strategy has been to gain tracktion through the major tech players. Think it's time for Stina to realize they cannot ignore the rest of us if they want to make it big.
For the most part there provided guis work wunderfully.
GPG is of course always a mess.
I agree with click to sign, that seems to be a bit hacky, otherwise however its fine.
Since USB-C is going to be the standard on computers, phones and tablets this new product will be very versatile and usable secure authentication across almost all devices [1]. Only question is - do apps like Yubico Authenticator and OpenKeyChain support this on Android already?
[1]: You're out of luck on iDevices of course, but you're out of luck with iDevices and Yubikey already.
[2]: This was much less of a problem for the first ~15 years of PGP's existence of course, but it feels old-fashioned nowadays.
However, my problem with USB-C is while it works great on my laptop, my desktop doesn't have a USB-C port anywhere near my desk or keyboard. I'd have to buy a hub or something. I'm sure this will get better as I find excuses to replace parts of my desktop hardware.
I'm surprised folks like the Neo though. I rarely use mine anymore as I kept accidentally triggering it when I carried my laptop to meetings.
(Slot 1 is click, Slot 2 is long click)
During a conference just make sure I don't have IRC on top.
> I rarely use mine anymore as I kept accidentally triggering it when I carried my laptop to meetings.
..for macOS there is statusbar application called YubiSwitch [1] which allows one to enable or disable their YubiKey (default keybind Alt + Cmd + Y). It has various useful features such as timeout (default 10 sec, feature disabled by default), or locking the computer if key is removed. I use it together with a YubiKey Nano 4, with a YubiKey Neo as backup.
Be sure to enter the right ProductID to make it work. You can only use one, so if you ever use your backup key you need to configure that ProductID.
I'll look into Yubiswitch, thanks!
Not a new problem for USB-C, of course.
If either is compromised, you can use the other to log in and block it.
Is there any potential for the Yubikeys to get "out of sync"? Or do you just initialize both Yubikeys upfront, and then distribute them to a safe place?
Generally I would just buy 2 however.
The first week I had it, I left it inserted in the computer a number of times. Now I keep it on my keys so that I don't forget to remove it.
Now I
(OTG too for various devices, of you want really wide compatibility)
[1] https://www.yubico.com/2016/05/secure-hardware-vs-open-sourc...
Edit: looking at the PIV tools manual they provide; I can see no mention of the tool supporting 521, it fails when I try to generate a key.
Looking through the .h files, I do see mentions of p521 ;)
int BN_nist_mod_192(BIGNUM *r, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx);
int BN_nist_mod_224(BIGNUM *r, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx);
int BN_nist_mod_256(BIGNUM *r, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx);
int BN_nist_mod_384(BIGNUM *r, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx);
int BN_nist_mod_521(BIGNUM *r, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx);They certainly don't come across as flimsy.
That said, I would rather use Google Authenticate (TOTP) for two factor. Getting my phone out is a regular thing. Getting the yubikey out and plugging it in seems more of a hassle. Passpack is the only thing I have to use the yubikey for -- would be happy if they provided TOTP. Spending $40 for two factor these days is kind of ridiculous.
Its not only more convinient, its also far, far safer then TOTP.
The will not support TOPT because that would require constant power.
You can get a U2F only stick for 18 bucks from them. Once in a while (for example when github interduced U2F the sell 2 for 5$).
https://www.yubico.com/support/knowledge-base/categories/art...
Then there's the concern about who has access to those keys when I'm not around.
I keep a backup key in a safe location, and my primary on my keychain which is typically in my pocket.
This is what I'm waiting for. Besides lower prices. There's just no way these things should cost more than $2.
[1] https://www.adafruit.com/products/2810?gclid=CLnuoLPDq9ECFQ1...
Pure FIDO U2F keys (USB, but also NFC and Bluetooth LE) however I would very much like to see hitting a $5 or lower price point. It would enable services to introduce proper two factor authentication without breaking the bank. At the moment these keys are just a bit too expensive (Yubico's USB-only U2F key costs $18; slightly cheaper in bulk).
Absent R&D costs, support costs, sales costs, and you know - actually making money...
Alternatively, I bet they could sell them for less and deny all future security issues or ask that you throw them away when they are inevitable discovered.
[1] https://www.yubico.com/2015/04/yubikey-neo-openpgp-security-...
and it's proprietary so only yubikey knows what kind of extra shit they're running on it.
Not that this isn't justifiable... just the way it goes when most of the cash goes into development perhaps.
These are crypto hardened chips with obfuscated ASIC layouts and other details to prevent things like power line attacks and decapping. These aren't quite your run of the mill commodity chips.
Furthermore, Yubico stands behind their product. When someone hacked the key with a power line analysis attack, they released updated firmware [1]. When someone hacked the OpenPGP applet that I use for SSH, they replaced my Yubikey Neo in a hassle free manner [2].
> Not that this isn't justifiable... just the way it goes when most of the cash goes into development perhaps.
When you factor in the cost of pretending that security devices don't have issues and compare it to the cost of actually handling those issues, it may not be so bad.
[1] https://www.yubico.com/2014/04/improvements-physical-yubikey...
[2] https://www.yubico.com/2015/04/yubikey-neo-openpgp-security-...
[0] https://www.yubico.com/2015/02/big-debate-2048-4096-yubicos-...
[1] http://www.nxp.com/documents/short_data_sheet/A700X_FAM_SDS....