Bitcoin Forum
May 08, 2024, 01:05:21 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Are Yubikeys really safe?  (Read 766 times)
Quantus (OP)
Legendary
*
Offline Offline

Activity: 883
Merit: 1005



View Profile
December 24, 2016, 05:53:11 AM
Last edit: December 24, 2016, 06:13:33 AM by Quantus
 #1

So I read http://arstechnica.com/security/2016/12/this-low-cost-device-may-be-the-worlds-best-hope-against-account-takeovers/

Then remembered I had a yubikey from MtGox but it was locked down so you couldn't reprogram it.

Then found this http://crypto.stackexchange.com/questions/14809/any-use-for-now-defunct-mt-gox-yubikey

But after unlocking it using the Yubikey personalization tool on the Yubikey website I got this.



It has OTP (one-time-pass) but not universal 2 factor authentication. I thought they were the same thing. I registered the key with Yubikey and then tried to pair it with Dropbox but it was not detectable to the website. (yes i was using Chrome)

Now I can still use it for 2 Static passwords (like something really random to pad my existing passwords or unlock my wallet) but I really want to utilize the One-time-pass feature on websites.  

I could just buy a new $18 dollar one from Yubikey... but I'm cheap, I also have questions about possible government take over or hacking of the Yubikey servers.

I hear their code is no longer open source.

Dose anyone else use these things or know of any alternatives?

Are they safe? The Private keys are stored on the Yubikey servers so they could be backdoored by the US government no?

I see that they sell a variety of products all based on the same hardware, but with different firmware. In fact, they advertise that firmware is upgradeable. This has me a little concerned. I'd feel a lot better about a security product, if the firmware couldn't be tampered with by malware.

(I am a 1MB block supporter who thinks all users should be using Full-Node clients)
Avoid the XT shills, they only want to destroy bitcoin, their hubris and greed will destroy us.
Know your adversary https://www.youtube.com/watch?v=BKorP55Aqvg
1715173521
Hero Member
*
Offline Offline

Posts: 1715173521

View Profile Personal Message (Offline)

Ignore
1715173521
Reply with quote  #2

1715173521
Report to moderator
1715173521
Hero Member
*
Offline Offline

Posts: 1715173521

View Profile Personal Message (Offline)

Ignore
1715173521
Reply with quote  #2

1715173521
Report to moderator
1715173521
Hero Member
*
Offline Offline

Posts: 1715173521

View Profile Personal Message (Offline)

Ignore
1715173521
Reply with quote  #2

1715173521
Report to moderator
You can see the statistics of your reports to moderators on the "Report to moderator" pages.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715173521
Hero Member
*
Offline Offline

Posts: 1715173521

View Profile Personal Message (Offline)

Ignore
1715173521
Reply with quote  #2

1715173521
Report to moderator
1715173521
Hero Member
*
Offline Offline

Posts: 1715173521

View Profile Personal Message (Offline)

Ignore
1715173521
Reply with quote  #2

1715173521
Report to moderator
1715173521
Hero Member
*
Offline Offline

Posts: 1715173521

View Profile Personal Message (Offline)

Ignore
1715173521
Reply with quote  #2

1715173521
Report to moderator
CoinCidental
Legendary
*
Offline Offline

Activity: 1316
Merit: 1000


Si vis pacem, para bellum


View Profile
December 24, 2016, 01:13:40 PM
 #2

be wary of anything and everything is the best advice anyone can give you .......
a paper wallet with bip 38 or equivalent maybe your best bet if
  your yubikey maybe compromised  for any reason
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!