Passwordless Logins with Yubikey
adl1995.github.io
adl1995.github.io
To login to my work VPN, the password is "<my pin><output from the yubikey>". Our SSO system requires both once per day as well.
It's a great system and I highly recommend it.
I like that set up, even though that’s a password manager and not like an ssh key held on Yubikey.
I believe there‘s a new biometric yubikey in the works. A fingerprint version of the 5C NFC would be cool.
That is, you aren't securing your vpn with two factors. You are securing access to your vpn. It is different.
Similarly, for your computer, it is already something you have. Such that the password to login to the machine can already be seen as a second factor. My home password, as an example, is worthless to you without me home computer.
I'm not sure on the argument regarding moving to a physical key to get in the machine. By and large, it seems to be a more transferable method of accessing something. Not more secure, per se. But not less, either. (Right?)
I will say that a security key is far easier to carry on you in more situations than say a laptop is and certainly a desktop. And the key, depending on how it is used to secure the device, may help mitigate brute force password attacks in the event that the device is stolen.
An argument could be made for defense in depth but for most people I would guess the amount of added security is probably not super beneficial and for those where it truly does matter then securing physical access to the device is probably more important any way.
That said, your phone is growing to take that privilege.
As I understand it, a yubikey is '"something you have" that we can reasonably verify as unique based on a shared secret with a third party.' That is, the algorithm that the yubikey is using to verify that it is something you have, is predicated on other knowledge, correct?
(I know I have one question mark up there. But I intend all of these assertions as a question. I'm not positive on this stuff.)
What makes hardware tokens (like the yubikey) fill this role better is that the algorithm (which is really pretty standard crypto) runs on the device and the device is specifically designed to not reveal its keys, so it's easier to assume that anyone that can present proof of the keys also has the physical object.
Secure enclave (and that is why I mentioned TPMs in the previous post although it seems like it would require a TEE) could fill the same role as a yubikey, but is often not used that way except for the device vendors login (like apple id). Even if your password is encrypted in a way that only the secure enclave can unlock if you can get it out of there then it is not as secure as something that you can only prove possession of (and not extract).
Just want to take this moment to remind everyone that the yubikey have a protocol to configure it. Nobody knows the code that runs that prototocol. Nobody knows the full capabilities of said prototocol. the best hint we have is the semi-opensource configurator python/cli utilities which are just a bitmashing client of the published capabilities.
thank you.
Still the idea of hardware tokes, u2f, WebAuthN is not at all tied to yubikeys and there are implementations of it that are software-opensource like solokeys.
I think the security of a yubikey is likely better than most alternatives even if it is not open to scrutiny anymore.
I'm also guessing this is the point where it would be good to mention that WebUSB was a vulnerability for u2f hardware tokens (if you gave sites permission to interact with USB devices): https://www.wired.com/story/chrome-yubikey-phishing-webusb/
Yep, it's generally been a useful combination. The "something you know" part could risk becoming a lower barrier the more that data breaches occur, and the more that people share and can infer about each other on public social media.
At the moment we tend to be very focused on securing individual identities and then assuring that what we say, do and write corresponds to those identities.
Perhaps a longer-term strategy is to care a bit less about the identity and be able to accept (and reject) content regardless of source.
You have to remember where we are starting from - most people are still using the same password across all their accounts.
There are a lot more people far away from you than there are close to you. If breaking your security requires physical proximity (such as to steal a yubikey), then you are much safer just based on this. It's also easier for people to blindly steal credentials for millions of people online than it is for them to steal millions of physical security keys.
Alternatively, passwords are commonly reused across websites, so a failure of any of those websites can lead to a compromise of all of them, which is not the case with a YubiKey. Along that same line of thought, passwords are phishable, where YubiKeys are not.
It's also possible that people in your physical proximity could shoulder surf your password, install a keylogger (which could be a physical keylogger, if you normally use a USB keyboard, not just software), or use a strategically positioned camera to do some digital shoulder surfing. Passwords aren't immune to trust issues when it comes to physical proximity. Ideally, you trust those you are near to some extent.
YubiKey also has a fingerprint-protected device coming out soon[0]... which would raise the bar for the threat model in this discussion some. Using a fingerprint and/or PIN to unlock a YubiKey preserves most of the benefits, while eliminating most of the concerns that people are mentioning. HSMs can choose to self-erase after a certain number of failed PIN attempts, so even a short PIN is not something that can easily be brute forced without an unpatched vulnerability.
If websites would allow you to only use any one of your YubiKeys to authenticate (obviously meaning you can have multiple, with backup YubiKeys stored somewhere safe in case you lose your main one), I think that would be a significant improvement in security over password authentication for most people. This is basically what the WebAuthn standard is attempting to do. I don't expect most people to be interested in buying 3 security keys and carrying one around all the time, though.
[0]: https://www.yubico.com/blog/yubico-reveals-first-biometric-y...
A lot of people outside your home are trying to hack you.
Shifting your exposure from "everyone in the world with an internet connection" to "people who are in/near your home" greatly reduces your risk, objectively.
I kindly propose everyone to forget all their passwords.
Then they mostly don't need second factor if they generate random password each time and don't care about remembering them at all.
They have a key coming (some day) which will also support a biometric factor.
https://www.openssh.com/txt/release-8.2
https://cryptsus.com/blog/how-to-configure-openssh-with-yubi...
TOTP with a PAM module is insecure since it's not cryptographically tied to the session like public key auth and can be phished. The author's suggestion to use it for passwordless login is dangerous when applied to SSH sessions!
99.7% of people will get their password stolen because they use only one on each service. It will get stolen on some shady site, and then checked against the same email on gmail.com.
The remaining 0.3% of the users will have their laptop stolen, together with the key. The thief will the re-image the laptop to sell it and throw the key away.
Finally, 1723 geeks in the world need to make sure they use 8 FA so they will be fine.
There are also enterprise users (35.8%) who will get something from their company which marry a PIN to an OTP and they will be fine.
In other words: yay yubikey! instead of password.
Note: the percentages not only are invented but do not add up to 100%. The first one is probably very, very underestimated.
I attached it to my key ring, and within about 8 weeks, the device was destroyed through the general wear and tear of being in my pocket. The plastic started chipping at one end of the device, and before the long the entire plastic shell shattered off completely exposing the board underneath.
Was a pretty big bummer, and kept me with going back to Authy. Are there any other hardware key/tokens that are maybe a bit more rugged?
If you want to check it out, we just pre-launched Solo v2 [1]. The USB-A version is a solid block of pcb. The USB-C has extra soldering between the connector and the external pcb shield. It's "metal solid", vs plastic around the connector.
The only annoying thing about it is that "/etc/pam.d/sudo" gets overwritten on every macOS system upgrade.
https://apple.stackexchange.com/questions/259093/can-touch-i...
You can use the "yubikey personalization tool" to change the format of the yubico otp that it emits, including appending a enter key. This is the way you'd want it set up for that, with the "tab"s unselected and the "enter" selected: https://cdn.zappy.app/791c95f1c203ef39fb71ea2809aa82a6.png
1. Get a smart ring like OMNI
2. Shove a USB hub and a contactless reader into your mouse, so if on the next poll your hand with a ring isn't on it - lock it all
Seriously though, if someone would start selling mice with contactless readers built-in, I'd buy a few.
Technically, yes, but how do you target it? This is impossible to extract the private key from it.
The former approach would look something like this; the "default=1" part skips the next directive (pam_u2f.so) when the test fails (i.e. when the user is not in the mandatory_u2f group):
auth [success=ignore default=1] pam_succeed_if.so user ingroup mandatory_u2f
auth required pam_u2f.so cue
[1] https://developers.yubico.com/pam-u2f/ "nouserok … Set to enable authentication attempts to succeed even if the user trying to authenticate is not found inside authfile or if authfile is missing/malformed."