Biometric YubiKey
yubico.com
yubico.com
2) The computer/OS doesn't have to support anything for this added feature.
I'd like it to work that way but when I'm reading the article it doesn't explicitly say that (only mentioning integration with Azure that's not interesting for me).
Is there any authoritative info that the fingerprint reader will work as touch button but with verification of fingerprints in all scenarios? (like touch-to-use on OpenPGP applet, U2F applet etc.)
Additionally, it prevents brute force attacks on the hardware.
Some hardware keys are being built into devices, or are left in them semi-perminately (to be fair, physical attacks arent a real concern for most people)
This works through an addon in the browser rather than native functionality but the system is secure enough that I use it as a backup for some of my 2FA services in case I lose my TOTP keys.
I don't think this product is as useful as it seems at first glance. Using stronger passwords is probably just as safe.
But I am no tptacek so I may be completely wrong :)
I do hope you realize this raises the amount of work the attacker has to do to actually get access to your device. It's a little like saying a second lock on your door is not going to stop anyone, but in practice statistics are clear: adding one more layer, even if that layer can be defeated as well, reduces the chance of a successful attack, or deters the attacker in the first place.
Anyway, Yubikey is only a second factor - not your entire security strategy - and I think it is made a bit stronger with a biometric, thats all.
The people most of us work with have physical access to our computers and they could probably shoulder surf a short password (use a password manager!). I don't imagine any of them could successfully lift a fingerprint sufficiently well to fool a biometric reader. It's looks easy in perfect conditions on YouTube but in the real world it's a bit harder.
I hope not anyway because my office has fingerprint access.
If you're looking to fix this, you can use the guide below.
> https://support.yubico.com/support/solutions/articles/150000...
You can switch to the long press slot.
You can remove the carriage return at the end of the sequence (so it doesn't hit ENTER for you).
It's a bit silly that the default implementation is so non-user-friendly.
I now have long-press disabled by default, but I used to be in a state of constant worry.
There are probably just different recognition technologies around and my phone probably uses a very cheap one.
Personally I don't really care about biometric protections, because they can very often with more or less effort be copied and faked and once they are leaked, you cannot change them easily yourself.
What I'd really like to see is government ID that works somehow similarly how domain certificates work - you can either use your Id as yubikey or authorize/mint multiple additional keys using same certificate chain...
My country Id has a chip that requires you to run java applet in browser. Nobody uses that shit. Other options are logging in via internet banking (people are flocking away from traditiona banks in europe to monese, revolut and the like) or via SMS while using special SIM card (requires paid membership from oligopolic mobile providers). It's so modern that you are locked out from your government digital services if you live abroad...
* You cannot leave your computer alone with Yubikey plugged in (especially useful when combined with modifying your PAM stack to lock the screen when yubikey is plugged out [2])
* Plugging Yubikey on a keychain which is bulky is cumbersome
* Yubikey on your neck can be a great conversation opener :)
[1] https://www.amazon.com/Updated-CarryLuxe-Lanyard-Polyester-R...
I've done it enough with wired headphones to know you never really acclimatize to having something hanging from your body
Nope, I'd like to see one too. In the mean-time Fidesmo card can replace some usages of Yubikey (U2F, OpenPGP): https://shop.fidesmo.com/products/fidesmo-card-2-0
Are there _any_ laptops with NFC? What other uses would it have?
The uses would be bulletproof authentication with client certificates. Your identities can live on a physical card (instead of “hacks” like password managers which are a pain to sync, etc) which you can use on any machine (laptop, phone) and taking the card away inherently prevents the machine from using your credentials down the line no matter how evil it is. It also allows your identities to be carried over from the physical world to the internet - your existing bank card can be used for online banking instead of a separate login that can be reset by an attacker, and your biometric passport or national ID card allows you to login to pay tax or similar government tasks.
Fingerprint are not very secure, but as this is meant to be only for physical access with the password, it's much better than before.
The use case we're all familiar with is that the YubiKey acts as the second (physical) factor. In that use case, this is great, because now you can opt to make the login three-factor: something you know (password), something you have (the fob), and something you are (your fingerprint).
However, Yubico has also been pushing the password-less login angle. If you look at the FIDO 2/WebAuthn standards and the new capabilities in the current generation of YubiKeys (YubiKey 5's), there's a new capability called a resident key. This removes the dependence on passwords entirely. Currently you can protect that key with a password. I believe this new thumbprint reader allows you to unlock the resident key with a thumbprint. That's what would bring it to parity with built-in thumbprint readers on laptops.
Passwordless login currently exists in the form of thumbprint readers (like on Thinkpads and those Samsung phones that recently showed they had a major flaw) and face recognition (laptops and phones). In the case of facial recognition, I think the convenience benefit is worth the security tradeoff. However, I'd be nervous about using passwordless fingerprint authentication on my YubiKey because that thing is so much easier to lose track of, and I don't trust fingerprint recognition.
The width supply chain of computers is enormous, and only a tiny fraction of computers available are interesting to compromise. This would make it astronomically expensive to compromise a significant fraction of all computers that are useful to compromise and the risk of detection would be fairly high. The market of security keys is relatively small and a significant portion are worth compromising, compromises there are much more effective.
If state actors do not completely compromise the manufacture of these keys then they are extremely incompetent and derelict in their duties.
Put another way, if the {pick your boogeyman state} government started issuing hardware cryptokeys and suggesting you use them as a single factor access to your servers, what would you think of that?
Would your opinion be improved if they just didn't announce that they were the boogeyman state and instead did business under a cover company?
Do you have any realistic means of determining that this isn't happening?
"I let someone else generate my secret keys for me" is a failure at the most basic level of security, and that failure isn't removed by them also putting the secret keys in a potted, opaque, and unauditable hardware device.
Yubikey as a second factor is a fantastic improvement-- it's a quite strong protection against attackers who couldn't compromise the keys.
Yubikey as a single factor is simply key escrow with extra steps.
Claiming that trusting the devices own 'fingerprint permission' is two-factor is deceptive since an attacker which has compromised the device's construction, design, or confidentiality of its state only faces one-factor security.
Do I understand that correct?
All the usb-c connectors I know have soldered body connections, which makes for a really poor mechanical bond. Solder joints are full of mechanical stresses and the only thing preventing a bend is the copper delaminating from the pcb.
In usb-a, any bending has to break the entire substrate. Decent plated contacts will outlast the connectors they're plugging into. On top of that you can plate something like a yubikey on both sides if you wanted to, so the only advantage is size and it's not like you're plugging these things into your phone. As long as computers still have a single usb-a (and they should, if only for backwards compatibility) it's a non-issue, IMO.
What I mean by solid strain relief is basically a plastic float that bridges the soldered connections to the connector body. I haven't seen one like that, but it's necessary to isolate the connector itself from the board and soldered bits. Covering the whole thing in goop helps for excessive force, but does almost nothing for the everyday wiggles that eventually cause connections to loosen. You need built in flex for that.
[1]: https://cdn10.bigcommerce.com/s-u7jmw/products/93/images/840...
Solokey is also pretty good.
With a high-quality product like a 2factor key, this may not be an issue. But wifi/bluetooth/SDR dongles and adapters get made to much lower standards and with cheaper solder. Cheap solder is far more prone to degradation.
[1]: https://i.shgcdn.com/25b75d64-fced-4845-acc5-91c39d0029bd/-/...
My next macbook, I'm definitely buying those 3rd party magsafe-like dongles that sit in my usb-c ports!
Do you have any recommendations on brands by any chance? I don't know anyone who has them, but I've been considering getting a couple for my phone and random devices that use usb-c.
The way I see it, I would want the bio version to be the one on my person. I still have the other put away where it won't be lost.
I lose my hand? Still have a backup. I lose my key? Backup and maybe I have a little bit of extra time to update my bank MFA while the thief figures out the fingerprint situation.
That's been my biggest struggle, I want a primary and backup key but almost every service I use only allows one at a time. I cannot duplicate the same key because it increments internally to avoid replay.
https://arstechnica.com/tech-policy/2017/03/man-jailed-indef...
With this key, that's already many less parts to verify and trust.
Let's hope it's not easily reverse-engineerable and the key is never shared with Yubikey.
The fingerprint is a third factor. Your password is the first. The physical key is the second. And the fingerprint is the third.
If your fingerprint is compromised, this system reverts to the security of a 2FA system with a normal physical token (i.e. very strong).
You plug the key into the Windows PC, and you put your fingertip on the sensor and you're signed in. That's two factors, "Something you have" and "Something you are" not three.
For your AWS sign in obviously it won't need a fingerprint and so it'd be kind of silly for the demo to be "this more expensive product works like the older cheaper product you already have" they wanted to show off the new feature which is the "resident credential" user verification mode.
It can prevent someone that gains physical access to your yubikey from easily using the device. It might not stop a very advanced attacker, but it at least makes things more difficult.
The fingerprint is not a password replacement. The yubikey is a password replacement. The fingerprint prevents a random person from using your yubikey before you notice that it’s gone and you revoke it.
And the fingerprint is absolutely not a good password replacement.
I have the Authenticator apps but it’d be nice if the phone and computer could exchange those numbers for me.
https://youtu.be/GMBL9bkboV4?t=25
(Disclosure: I work at IBM, but not on this)
"In keeping with Yubico’s design philosophy, the YubiKey Bio will not require any batteries, drivers, or associated software."
It's actually easier to support this in Linux than a "conventional" PIN-based FIDO2 token because the Linux system doesn't need to arrange to read a PIN from the user and send that to the token, the token is going to read the user's fingerprint instead.
If you just want a second factor, it'll work like an old FIDO device, which you might be familiar with for U2F - everything is already in place, loads of people are doing this including with Yubico's existing FIDO2 (pin-based) product.
If you want this to be the sole factor (as in the Windows demos or for a site where the convenience of one touch login is good but you don't need MFA security) that ought to work with WebAuthn out of the box, but I actually haven't seen a demo, so I can't say this from personal experience even though I own a FIDO2 token.
‡ Referring to "Go usernameless too" which is the mode where a PIN is needed. All the other modes are just plain FIDO and don't need any further verification, and they work just fine on all my systems with any of my tokens.
Using the FIDO2 Yubikey as sole source of truth replacing usernames and passwords is not available in U2F that's a WebAuthn feature only and apparently it doesn't work in Firefox yet which is disappointing.
Is that a problem now?
For Firefox since they advertise support for WebAuthn I /presume/ that the browser will do all the PIN prompts and so on to make this work, but again I have never seen this even _demonstrated_ let alone used in anger. The browser feature doesn't help you if the PC has booted and is at the login screen though, no browser there (yet?).
I own a device (Yubico's own "Security Key 2") which supports this workflow and I've played with it on a demo Windows setup, and though I'd probably never use it to sign into my Linux PCs I'd try it out because I'm a nerd. This device works fine as a FIDO key for my WebAuthn accounts and is enrolled at GitHub etcetera for that purpose but then so does my much cheaper Key-ID FIDO key.
Edited to add: There are a couple of replies now talking about non-FIDO flows like Smartcards or whatever. Some of Yubico's other devices can do these, but we're talking about FIDO2 like this new Yubikey, those flows aren't relevant.
I login to my Linux desktops with a Yubikey and its PIN. I have it configured as a OpenPGP smartcard, and to authenticate (for login, raising privileges with sudo, or unlocking the screen, etc.), I use the poldi[1] PAM module.
Getting the public key out from an OpenPGP smartcard otherwise is not supported by the protocol it uses. That is frustrating that it wasn't included in the procotol, but I've gotten over it.
After you've imported the public key, getting the private key stubs is a matter of checking the status of the card with `gpg --card-status`. The stubs are added then.
If you have another machine that has the public key, you can export it with `gpg --export -a $key_identity`, and import it with `gpg --import < $exported_public_key_file`.
Otherwise, if you don't hold another copy of the public key, the only option left might be to make a new keypair and be careful to not lose all copies of the public key again.
Also, if you backup the private key, you can get the public key from it by importing it somewhere.
Just because this or some other Yubico devices might not allow it doesn't mean others don't. AFAIK for instance Feitian ePass supports GIDS applet, which you can install on smartcards too. And yes, you can install U2F applet on smartcards also.
https://www.rcdevs.com/docs/howtos/epass/epass
https://www.ftsafe.com/Products/FIDO/NFC
Why people are not rooting and fighting for an ability to extend things with open source is beyond me.
but I haven't tried it out.
> The key seamlessly integrates with the native biometric enrollment and management features supported in the latest versions of Windows 10 and Azure Active Directory, making it quick and convenient for users to adopt a phishing-resistant passwordless login flow.
So I'm also curious if this indicates that biometric enrollment is not going to be added to yubikey-manager or yubico-pam.
FWIW, the current YubiKey does everything on the device, not much of a stretch for it to also do the fingerprint sensing there too.
I think the concern is how would you tell the key that you want to enroll a fingerprint with it? On Windows, you'd use Windows software, but Linux has no such biometric management software as far as I know.
$ ykmgr bio enroll
This will surely need enough computer help to initiate the process, but the actual biometric data is likely on the dongle itself.
Alternatively, the dongle could produce a wrapped key blob that contains a fingerprint. This would look almost like a normal FIDO enrollment and would allow multiple users to share one dongle with access to different keys.
Hopefully. The concern is if what the article says is indication that they won't, or at least not for some time. Does "does not require associated software because Windows doesn't need it" mean that they didn't see a point in making the associated software for a user minority? That's what I think the concern is.
For a fingerprint (or like, I dunno, a pinprick blood sample, or maybe they'll make one that requires a freshly plucked hair from your head) that enrollment step just adds a boolean flag saying the Relying Party demands the user's identity be verified by the device during enrollment and any subsequent authorisations.
It's sort of on the honour system, except, if you actually demanded this (maybe in a corporate environment?) FIDO has a mechanism for devices to provide a certificate proving which batch of devices they're from, so you could say OK, I trust Yubico's BioKey 4.1 and BioKey 4.2 and the FooCorp EyeBallSlicer 1000 but any other devices aren't allowed to enroll. If you then found out the BioKey 4.1 can be fooled by breathing on it instead of a fingerprint you'd remove that from your whitelist.
Firefox (and maybe Chrome?) let you blank this out basically, so sites can either accept that you won't tell them what device it is or they can refuse to let you enroll. I can imagine _maybe_ making an exception for my bank or government, but any other site can fuck right off.
If you want to see how a native app can talk to the YubiKey, you can play with Yubico's own implementation: https://github.com/Yubico/python-fido2/
For browser based code, you can use WebAuthn and leave the device communication to the browser and OS: https://developer.mozilla.org/en-US/docs/Web/API/Web_Authent...
https://github.com/Yubico/yubikey-manager/
For example, it is possible to configure whether user interaction is necessary before encrypting:
ykman openpgp set-touch enc off
The program will probably gain support for fingerprint configuration when the new YubiKeys are released.The flagship YubiKeys can also act like a smart card. They are PIV compatible and support X.509 certificates. They can also store encryption, authentication and signing OpenPGP keys. GNU Privacy Guard opens the YubiKey as if it was a smart card.
Then put the 2nd in a locked safe or other location that requires someone to have absurd access.
If you lose the 1st, use the 2nd to deregister the 1st and register a 3rd.
Having a reliance on 1 individual creates a great deal of risk, not just in the case of lost YubiKeys.
Relying on recovery methods for all your yubikey secured accounts would be a vast amount of work.
You could generate keys off the device and keep a copy elswhere allowing you to revoke the device's sub key and generate a new one for a replacement device.
You could have two, and only carry one. (Big downside is that you need to fish out the backup every time you register for something new.)
You could use something else as a second factor as well, and just treat the device as a more convenient option than looking up and typing in an TOTP code, say.
Then they take the Yubikey.
Then they take your eyeballs and your fingers.
I'm not so sure I want to encourage them to do #3.
This is not the threat model being used here. This feature is meant to protect you when you forget your yubikey on your laptop while on lunch break, allowing any co-worker from logging in/using the GPG keys stored within.
Also, just a nit, iPhones aren't purely biometric. You have to input your pin after reboot or a long period of inactivity. I'll agree it's still a bit too close to being a password for comfort though.
Something I have: The Yubikey (hardware key)
Something I am: The fingerprint (biometrics)
So this Yubikey enables 3FA.
Passwords are normally also protected from bruteforce. Many places lock you out for some time after many failed attempts.
The "PINs are for devices" seems kind of arbitrary.
https://en.wikipedia.org/wiki/Personal_identification_number
Fundamentally, I think PINs in the traditional sense are just passwords with a tradition of particular password requirements.
You can also mention passphrases and say how they're different from passwords, but you can put passwords in fields labeled passphrases and passphrases in fields labeled passwords. They're all functionally the same.
EDIT: From the Password Wikipedia article[1]
> In general, a password is an arbitrary string of characters including letters, digits, or other symbols. If the permissible characters are constrained to be numeric, the corresponding secret is sometimes called a personal identification number (PIN).
https://docs.microsoft.com/en-us/windows/security/identity-p...
> In common usage, PINs are used in [...] internet transactions or to log into a restricted website.
EDIT: Also, the IRS uses PINs online[1]:
> Your IP PIN will be displayed to you online once we verify your identity. A new IP PIN is generated for each filing season and can be retrieved starting in mid-January of each year by logging into the account you create.
They even allow you to enter it on paper[2]:
> Paper Return: [...] Enter your IP PIN(s) as applicable in the boxes marked "Identity Protection PIN" in signature area of the return.
EDIT 2: There are also many employee time-clocks that use PINs to authenticate the employees, like this one[3]. You can connect to them through the network to export some nifty reports that includes everyone's PIN, like this one[4].
I'm sure use of PINs is also common with ERPs and POS systems (to authenticate a cashier supervisor authorizing some action), and those are also networked.
EDIT 3: On the Microsoft link you provided, they're talking specifically about the PINs in Windows 10. I wouldn't take that page as talking about all PINs in general.
[1] https://www.irs.gov/identity-theft-fraud-scams/get-an-identi...
[2] https://www.irs.gov/identity-theft-fraud-scams/frequently-as...
[3] https://www.alliedtime.com/Compumatic-XLS-21-Badge-Time-Cloc...
[4] https://www.alliedtime.com/v/vspfiles/assets/images/pdfs/com...
But this device is a simply a step up from the non-biometric enabled units which you can buy today.
So any belief this implies only your permission-ed access to your work is moot: If its not your computer, you probably don't have an implied right to privacy anyway, and a yubikey with bio isn't going to give you it either.
(maybe a non sequiteur, but some people may be assuming this means your local U2F bearing host is YOUR host, but.. not always)