Testing FIDO U2F security keys
imperialviolet.org
imperialviolet.org
But in fact there are almost certainly commercial hardware security keys that receive no testing at all at the level AGL is working at --- which, while impressive and super interesting, isn't as low-level as serious third party specialized crypto validation goes.
My takeaway from this is: buy the most popular U2F key (which happens to be Yubico's). This isn't a place where you want to shop around for interesting alternative brands.
Nobody pays me to say this and I have no relationship with Yubico of any sort.
I like and recommend the Yubikeys as well (not that my opinion is worth anything) and, other than that one "PIN bypass" issue in the OpenPGP applet on some NEOs [1] (which was inherited from upstream), I don't recall hearing of any issues with them. There may be better devices out there but I'm sure there are much worse ones that you could buy (as AGL just showed us) and I'm quite happy with my (~7!) Yubikeys.
ETA: "The YubiKey ... meets the highest level of assurance (LOA) requirements, based on NIST Electronic Authentication Guideline SP 800-63-2 ..." [2].
[0]: https://www.yubico.com/products/yubikey-hardware/compare-yub...
[1]: https://developers.yubico.com/ykneo-openpgp/SecurityAdvisory...
[2]: https://www.yubico.com/wp-content/uploads/2016/06/Yubico_Whi...
1. https://www.blackhat.com/us-17/briefings/schedule/index.html...
All things being equal, though, I would still be inclined to have a little more trust in something that has been through the process than I would in, say, the homebrew RNG [0?] used by Honest Achmed's Used Cars and Certificates.
FYI, I was making a reference to a "bug" from 6.5 years ago: https://bugzilla.mozilla.org/show_bug.cgi?id=647959
(another HN'er thought this was a "little racist")
(1) unless you use the reference to put it into context, or discuss it, ...
I'm over all the politically correct bullshit and people actively looking for things to be offended by. It wasn't meant to be racist. It was meant to illustrate a point. I come to HN to get away from all of that shit so, please, go be offended by something else.
The two popular options are: Trezor and Ledger. Both supports FIDO U2F and have a large user base.
For SSH authentication, I use Yubikeys (and only Yubikeys) everywhere: my workstation at home (I WFH 99% of the time), my primary laptop, and a "backup" laptop. Each of these machines has its own "dedicated" Yubikey that I use to authenticate to remote SSH servers (a "Nano" that is left plugged in 24/7). I also use these (with challenge/response) to unlock encrypted LUKS volumes (containing ZFS pools) at boot, FWIW.
I would like to begin using U2F (AFAICT, U2F support should be coming to Firefox soon, if it hasn't already; running FF57 Developer Edition here), preferably with these same Yubikeys I am already using for SSH. If there are any issues, however, I'm fine with using a separate Yubikey just for the U2F side of things (I have a few U2F-only Yubikeys laying around as well).
Basically, I want it to be as easy/convenient as possible and, before I begin to attempt this, I'm just curious if anyone else is already doing this and, if so, what their experiences were and any issues they may have encountered. In theory, it should all just work but, in reality, well, who knows. TIA!
Occasionally whichever applet I'm attempting to use will appear unavailable, requiring the token be pulled and reseated.
Thanks.
alias gpgpls='gpg-connect-agent reloadagent /bye'
I haven't needed to pull the key since. I'm on macOS and use gpg-agent, U2F and yubioath-desktop.Then you get keys protected by hardware. Though the TPMs might commonly be easier to physically hack than good USB devices.
For other smartcard-y things: a lot of stuff gets called a "smart card", but any given application is going to involve a particular applet on a smartcard, and a particular client side implementation to use it. The Windows virtual smart card implements a PIV applet, I believe, whereas most of the Yubico stuff works using either non-standard applets or a PGP smartcard applet. So the client side would not be compatible with the Windows virtual smartcard.
See the details on Mozilla's Wiki [0] (short version: in "about:config", enable "security.webauth.{u2f,webauthn}") and visit Yubico's online demo [1] to test it out.
[0]: https://wiki.mozilla.org/Security/CryptoEngineering#Using_U2...
* By necessity there's a pretty large attack surface, you've likely got a vendor specific bluetooth stack and coprocessor. The same goes for wired solutions with hardware USB peripherals (though atleast significantly less complex). Being sure the hardware peripheral doesn't have any major memory safety issues is a complete bear to test, and that's not even touching on sidechannel analysis.
* Running public key crypto on microcontroller (excluding specific hardware crypto support) is a little more novel than a desktop machine, the leading libraries are no where near as extensively battle tested. And there's architectural concerns about sidechannel attacks and often the lack of any memory protection units (bigger chips solve these issues, but power budget concerns are tricky).
* And given all software has bugs, how do you update the firmware? Signed firmware patches as part of driver update? Who's to say somebody hasn't already owned your bootloader.
I think the solution to all this, is to abandon the idea of additional hardware, what if your smartphone could act as a two factor hardware token over Bluetooth? The big problem is pairing really, and how to make this an easy process for users, I never figured that out. On the other hand I did come up with a scheme that would allow usb based hardware tokens to work without additional drivers / software and on all current major operating systems and browsers. I really ought to work on it, but as above I don't trust embedded hardware (embedded hardware is such an antithesis to, move fast and break things).
I think the Bloomberg auth units are some of the most advanced examples of this - they're protected against almost any imaginable physical attack, too (freezing memory state, power sidechannels, xray/delidding to dump mask ROM, etc.) But they have a lot of money to spend on it...
I'm glad my hardware security token is not running a full smartphone OS updated only with delay and for a few years until the vendor wants me to buy a new one, does not connect to public wifi and mobile networks, won't run games and other third party software, does not break after falling from waist height.
[0]: https://www.ledgerwallet.com/
[1]: https://trezor.io/
However, I hope it improves in the future. The Ledger wallet can do:
1. FIDO/U2F
2. SSH/GPG
3. Password Management
4. Wallet for Bitcoin, Ethereum and a bunch of other altcoins.
So, yes, I think it is worth the deal.
I know that Yubico offers an NFC-enabled on, but it doesn't support 4096-bit keys if I understand correctly.
Any opinions on this product from the HN crowd? E.g., what do you think about the security implications of their user-installable applet model?
BankID isn't operated by the government but rather by the system critical banks however it's really ubiquitous today and supported by most government sites, banks and other high security web systems.
BankID comes both as hardware keys with smartcards or as a mobile application where you use a local key to sign a request.
I mean, comparing U2F keys with the alternative 2FA methods (like SMS and Google Authenticator), it sure seems simpler to just tap the USB key instead of taking out your phone, unlocking it, seeing the message, and writing the code from the message.
They're convenient as hell.
And that's why we have Yubikey Nano versions. And as for them being fragile, I really don't experience that. Mine one has been sitting on my keychain for about a year and a half and it seems rock-solid. Even though it has been through rains and thrown around countless times, it still works like it did on the day one. Even though it's plastic, it is pretty durable from my perspective.
It only worked with some sites that I tried, for others you probably have to fake the user agent.
Works perfectly for me.
Unfortunately, it seems that they've failed with shipping U2F support in Firefox at the time, so the browser support seems to be coming to 58 (currently in Nightly). So, your options in November will be either Firefox ESR or switching to Firefox Beta.
EDIT: Source: https://github.com/prefiks/u2f4moz/issues/59#issuecomment-32...
EDIT2: My previous coworker also discovered some high-CPU issues with that add-on on Ubuntu, so be aware of that as well: https://github.com/prefiks/u2f4moz/issues/51