To login to my work VPN, the password is "<my pin><output from the yubikey>". Our SSO system requires both once per day as well.
It's a great system and I highly recommend it.
To login to my work VPN, the password is "<my pin><output from the yubikey>". Our SSO system requires both once per day as well.
It's a great system and I highly recommend it.
That is, you aren't securing your vpn with two factors. You are securing access to your vpn. It is different.
Similarly, for your computer, it is already something you have. Such that the password to login to the machine can already be seen as a second factor. My home password, as an example, is worthless to you without me home computer.
I'm not sure on the argument regarding moving to a physical key to get in the machine. By and large, it seems to be a more transferable method of accessing something. Not more secure, per se. But not less, either. (Right?)
I will say that a security key is far easier to carry on you in more situations than say a laptop is and certainly a desktop. And the key, depending on how it is used to secure the device, may help mitigate brute force password attacks in the event that the device is stolen.
An argument could be made for defense in depth but for most people I would guess the amount of added security is probably not super beneficial and for those where it truly does matter then securing physical access to the device is probably more important any way.
That said, your phone is growing to take that privilege.
As I understand it, a yubikey is '"something you have" that we can reasonably verify as unique based on a shared secret with a third party.' That is, the algorithm that the yubikey is using to verify that it is something you have, is predicated on other knowledge, correct?
(I know I have one question mark up there. But I intend all of these assertions as a question. I'm not positive on this stuff.)
What makes hardware tokens (like the yubikey) fill this role better is that the algorithm (which is really pretty standard crypto) runs on the device and the device is specifically designed to not reveal its keys, so it's easier to assume that anyone that can present proof of the keys also has the physical object.
Secure enclave (and that is why I mentioned TPMs in the previous post although it seems like it would require a TEE) could fill the same role as a yubikey, but is often not used that way except for the device vendors login (like apple id). Even if your password is encrypted in a way that only the secure enclave can unlock if you can get it out of there then it is not as secure as something that you can only prove possession of (and not extract).
Just want to take this moment to remind everyone that the yubikey have a protocol to configure it. Nobody knows the code that runs that prototocol. Nobody knows the full capabilities of said prototocol. the best hint we have is the semi-opensource configurator python/cli utilities which are just a bitmashing client of the published capabilities.
thank you.
Still the idea of hardware tokes, u2f, WebAuthN is not at all tied to yubikeys and there are implementations of it that are software-opensource like solokeys.
I think the security of a yubikey is likely better than most alternatives even if it is not open to scrutiny anymore.
I'm also guessing this is the point where it would be good to mention that WebUSB was a vulnerability for u2f hardware tokens (if you gave sites permission to interact with USB devices): https://www.wired.com/story/chrome-yubikey-phishing-webusb/
Yep, it's generally been a useful combination. The "something you know" part could risk becoming a lower barrier the more that data breaches occur, and the more that people share and can infer about each other on public social media.
At the moment we tend to be very focused on securing individual identities and then assuring that what we say, do and write corresponds to those identities.
Perhaps a longer-term strategy is to care a bit less about the identity and be able to accept (and reject) content regardless of source.
I believe there‘s a new biometric yubikey in the works. A fingerprint version of the 5C NFC would be cool.
I like that set up, even though that’s a password manager and not like an ssh key held on Yubikey.