Yubikey - Help secure your digital assets.
0) Why Look into This1) Info From Manufacture2) The Products3) Lastpass4) Some Sites integrated with Yubikey Support(Including Blockchain.info!)5) Conclusion6) How to purchase1) Why look into this?Almost everyday we can see posts of someone losing their account in Meta on the forum. This caused me to ask myself what is the reason? And what can we do to stop it along with pushing security more. The anwser varies from lack of good security procedures such as using same password on more than one site, to losing it to attacks including malware and phishing.
It is enough of a problem to look into possible options. I have been using hardware wallets, and really liked the physical element added to your security. I knew I wanted a physical key as part of my security on other security solutions, which is what brought me to Yubikey.
1) Info From ManufactureA YubiKey is a small device that you register with a service or site that supports two-factor authentication. Two-factor authentication means that each time you log in, the service will request proof that you have your YubiKey in addition to your regular username and password. Phishing, malware, and other attack methods don’t work because they would need both your physical key and your passwords to breach your accounts.
To put it simply Yubikey is a physical key you can use to secure many of your digital assets. This includes everything from 2 factor Gmail accounts, Blockchain.info wallets to entire storage of passwords working with programs such as LastPass.
2) The Products:Above you will see three different Yubikey's. I wanted to try multiple versions as the one best for you can depend on your needs. I ended up testing the Yubikey 4, Yubikey 4 Nano, and the Yubikey Neo. There are differences depending on if you want a full size to small, or even nfc. To see all the differences look here:
https://www.yubico.com/products/yubikey-hardware/3) LastpassThis program is great for your password storage. I did use a premium version for 12 dollars a year, there is a trial and also a free version. It has a lot of really good features, the biggest was being able to combine a regular password with my Yubikey. So a great 2 factor storage system for password management.
I cannot cover all the features which you can find here:
https://lastpass.com/features/ . But I can cover my favorite features.
Store Passwords in a Secure Vault- All of your passwords and notes are stored safely in a vault. Easy-to-use, searchable, and organized the way you like.
One Account or Many- Have multiple Gmail accounts? 12 WordPress logins? Save unlimited logins for websites, and easily switch between them.
Generate Random Passwords- The built-in password generator will create long, randomized passwords that protect you from being hacked.
2 factor Authentication - Tie a "master password" with your Yubikey
Again to put this simply it means I can store my passwords safely, using a 2nd factor authentication. Even if I was to be compromised without my Yubikey an attacker cannot access my passwords stored within Lastpass. It allows for multiple accounts and makes this very easy, which is great if you are like me juggling Gmail accounts.
There is a possibility still if your computer was compromised to intercept username/password when entering into a website. The next section are some sites you can use Yubikey as a part of your login with 2 factor security.
4) Some Sites integrated with Yubikey Support(Including Blockchain.info! )Gmail and Google Apps
Dropbox
Blockchain.infoAbove are some of the main sites for me, but there are others out there. The main one and perhaps one of the biggest reasons I decided to try it was support with blockchain.info . This means even if you logged into your blockchain wallet from a comprised system the password alone is not enough to login. Without physical access of your Yubikey a "bad guy" is not going to be able to log in. Below is how to sit this up with BlockChain.info
1) From within your blockchain.info account click the account settings button
2) Click continue on the warning about sensitive data.
3) Enter you password for your account to access the account settings.
4) On the side menu click on the security option.
5) Click on the Two Factor Authentication drop down box and select Yubikey.
6) After selecting Yubikey click on the box below it and press your Yubikey button, you will see "Yubikey Successfully Updated" when successful .
7) Make sure to enter a secret phrase and save it in case you lose your Yubikey. I suggest storing it somewhere safe, as it will help recover your wallet access if you lose your Yubikey.
8 ) Now you can see your new blockchain.info login which requires your Yubikey as 2nd factor authentication!
5) ConclusionThis is a great tool to help you become more secure in your digital world. You can combine it with sites that have Yubikey integrated such as blockchain.info, or use it with password managers such as lastpass. These are great tools to help you keep good security practices.
Can it protect you from every possible compromise? Not as long as there are sites that do not require dual factor authentication. But if programs such as lastpass have you use unique and secure passwords that are different for each website, you have an advantage over a shared password used on multiple sites. And with Yubikey giving you 2nd factor authentication on sites such as google, and blockchain it is definitely something to consider.
5) How to purchaseBelow is link to order direct
1) Direct -
https://www.yubico.com/products/yubikey-hardware/