Bitcoin Forum
May 26, 2024, 07:34:33 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Mt. Gox - are OTPs generated by Yubikeys time-dependent?  (Read 1152 times)
ripper234 (OP)
Legendary
*
Offline Offline

Activity: 1358
Merit: 1003


Ron Gross


View Profile WWW
August 09, 2012, 01:41:22 PM
 #1

If I use a Yubikey on Mt. Gox, can a trojan capture this key, and reuse it some time in the future?

Actually, if you are using a MtGox yubikey as 2FA, you are similarly not protected by keyloggers - they don't validate the whole token, they just use the first so many digits (the serial number of the key) as the second factor.  Angry
Unfortunately, LastPass does the same damn thing for offline access.  Angry
[/quote]

Please do not pm me, use ron@bitcoin.org.il instead
Mastercoin Executive Director
Co-founder of the Israeli Bitcoin Association
rjk
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


1ngldh


View Profile
August 09, 2012, 01:48:17 PM
 #2

If I use a Yubikey on Mt. Gox, can a trojan capture this key, and reuse it some time in the future?

Actually, if you are using a MtGox yubikey as 2FA, you are similarly not protected by keyloggers - they don't validate the whole token, they just use the first so many digits (the serial number of the key) as the second factor.  Angry
Unfortunately, LastPass does the same damn thing for offline access.  Angry
You are reading my statement wrong. I was saying that specifically about blockchain.info. On MtGox, the yubikey is still a one-time password generator, although it never has been time dependent. It is not a TOTP token. Read more at http://yubico.com/

Mining Rig Extraordinaire - the Trenton BPX6806 18-slot PCIe backplane [PICS] Dead project is dead, all hail the coming of the mighty ASIC!
ripper234 (OP)
Legendary
*
Offline Offline

Activity: 1358
Merit: 1003


Ron Gross


View Profile WWW
August 09, 2012, 02:03:46 PM
 #3

You are reading my statement wrong. I was saying that specifically about blockchain.info. On MtGox, the yubikey is still a one-time password generator, although it never has been time dependent. It is not a TOTP token. Read more at http://yubico.com/

So, you mean that every password generated by a Yubikey can only be used once on Mt. Gox ... but that one time can be in whatever time in the future.

Suppose I generate a Yubikey, and for fun just generate an OTP into notepad, to test that it works.
Then, I connect to Mt. Gox, and use the Yubikey to generate another OTP.
If a Trojan sniffs the first OTP, will it be able to use it later on to login?

Please do not pm me, use ron@bitcoin.org.il instead
Mastercoin Executive Director
Co-founder of the Israeli Bitcoin Association
rjk
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


1ngldh


View Profile
August 09, 2012, 02:04:55 PM
 #4

You are reading my statement wrong. I was saying that specifically about blockchain.info. On MtGox, the yubikey is still a one-time password generator, although it never has been time dependent. It is not a TOTP token. Read more at http://yubico.com/

So, you mean that every password generated by a Yubikey can only be used once on Mt. Gox ... but that one time can be in whatever time in the future.

Suppose I generate a Yubikey, and for fun just generate an OTP into notepad, to test that it works.
Then, I connect to Mt. Gox, and use the Yubikey to generate another OTP.
If a Trojan sniffs the first OTP, will it be able to use it later on to login?
If you generate an OTP, it can be used any time in the future unless you generate another one and use it. Using a later OTP invalidates all previous OTPs.

Mining Rig Extraordinaire - the Trenton BPX6806 18-slot PCIe backplane [PICS] Dead project is dead, all hail the coming of the mighty ASIC!
ripper234 (OP)
Legendary
*
Offline Offline

Activity: 1358
Merit: 1003


Ron Gross


View Profile WWW
August 09, 2012, 02:07:33 PM
 #5

You are reading my statement wrong. I was saying that specifically about blockchain.info. On MtGox, the yubikey is still a one-time password generator, although it never has been time dependent. It is not a TOTP token. Read more at http://yubico.com/

So, you mean that every password generated by a Yubikey can only be used once on Mt. Gox ... but that one time can be in whatever time in the future.

Suppose I generate a Yubikey, and for fun just generate an OTP into notepad, to test that it works.
Then, I connect to Mt. Gox, and use the Yubikey to generate another OTP.
If a Trojan sniffs the first OTP, will it be able to use it later on to login?
If you generate an OTP, it can be used any time in the future unless you generate another one and use it. Using a later OTP invalidates all previous OTPs.

I see, thanks for clarifying.
Someone should write an "OTP for Bitcoin dummies" article.

Please do not pm me, use ron@bitcoin.org.il instead
Mastercoin Executive Director
Co-founder of the Israeli Bitcoin Association
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!