Bitcoin Forum
May 12, 2024, 12:27:19 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: 1 2 [All]
  Print  
Author Topic: I received my free Yubikey from MtGox today  (Read 4497 times)
geek-trader (OP)
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


View Profile
July 16, 2011, 06:19:16 AM
 #1

It's little, the "up" side (when plugged into my MacBook Pro) has a small copper circle that you press.

When logging in you press it for 1/2 second.  When you release, it sends a string of text to the MtGox "Yubikey" input field.

I have not done a withdrawal yet, but my understanding is that you press it for 3 seconds (instead 1/2 a second), and it sends a different string.


When you first plug it in, OS X thinks it's a keyboard, but you can just cancel out of that, and it works fine.

With this, I'm confidant that my MtGox account is safe from hackers.  Is my MtGox account safe from MtGox?  I don't know, but they have all the volume, so they have me for now.

Make 1 deposit and earn BTC for life! http://bitcoinpyramid.com/r/345
Play my FREE HTML5 games at: http://magigames.org  BTC donations accepted.
1715473639
Hero Member
*
Offline Offline

Posts: 1715473639

View Profile Personal Message (Offline)

Ignore
1715473639
Reply with quote  #2

1715473639
Report to moderator
1715473639
Hero Member
*
Offline Offline

Posts: 1715473639

View Profile Personal Message (Offline)

Ignore
1715473639
Reply with quote  #2

1715473639
Report to moderator
1715473639
Hero Member
*
Offline Offline

Posts: 1715473639

View Profile Personal Message (Offline)

Ignore
1715473639
Reply with quote  #2

1715473639
Report to moderator
In order to get the maximum amount of activity points possible, you just need to post once per day on average. Skipping days is OK as long as you maintain the average.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715473639
Hero Member
*
Offline Offline

Posts: 1715473639

View Profile Personal Message (Offline)

Ignore
1715473639
Reply with quote  #2

1715473639
Report to moderator
rate5
Member
**
Offline Offline

Activity: 104
Merit: 100



View Profile
July 16, 2011, 10:46:02 AM
 #2

Glad to hear you got your free Yubikey from mtgox.  They look cool I am thinking of buying one.
RyanWebber
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
July 16, 2011, 11:01:51 AM
 #3

Definately worth having if you're involved in high volume trading there. I'll probally buy one soon cause I'm pretty paranoid after the previous cluster §$%¤

If I have been remotely useful feel free to donate:
1DgkA1S64CoVGu1q5JFSz4maRQJYw2dMC8
elggawf
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
July 16, 2011, 12:59:03 PM
 #4

What were the requirements to get a free one?

^_^
RchGrav
Full Member
***
Offline Offline

Activity: 150
Merit: 100


View Profile
July 16, 2011, 05:40:16 PM
 #5

What were the requirements to get a free one?


If you had an active order to purchase BTC at the time of the breach..  you are eligible.


4C 6F 6E 67  4C 69 76 65  42 69 74 63 6F 69 6E
Qba'g lbh unir nalguvat orggre gb qb?
geek-trader (OP)
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


View Profile
July 16, 2011, 06:51:15 PM
 #6

What were the requirements to get a free one?

I had a trade nullified by the rollback after the hack.

Make 1 deposit and earn BTC for life! http://bitcoinpyramid.com/r/345
Play my FREE HTML5 games at: http://magigames.org  BTC donations accepted.
Jack of Diamonds
Sr. Member
****
Offline Offline

Activity: 252
Merit: 251



View Profile
July 16, 2011, 07:02:27 PM
 #7

I also got a free one a while back, have to say I can really sleep at ease now even with significant $$ or BTC stored in the account.

Spent time researching how feasible it is to crack Yubikey authentication, seems to be very infeasible so I trust it for now.

Negative side, it's bound to Mt. Gox so you can't use it as a normal YK on any other site.

1f3gHNoBodYw1LLs3ndY0UanYB1tC0lnsBec4USeYoU9AREaCH34PBeGgAR67fx
RchGrav
Full Member
***
Offline Offline

Activity: 150
Merit: 100


View Profile
July 16, 2011, 07:28:41 PM
 #8

I also got a free one a while back, have to say I can really sleep at ease now even with significant $$ or BTC stored in the account.

Spent time researching how feasible it is to crack Yubikey authentication, seems to be very infeasible so I trust it for now.

Negative side, it's bound to Mt. Gox so you can't use it as a normal YK on any other site.

Not really that negative from a security standpoint..  I have evaluated the Yubikey solution and can confirm that a higher degree of both security and functionality is possible when it is used in a site specific fashion.

4C 6F 6E 67  4C 69 76 65  42 69 74 63 6F 69 6E
Qba'g lbh unir nalguvat orggre gb qb?
d.james
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250

Firstbits: 12pqwk


View Profile
July 16, 2011, 09:22:05 PM
 #9

What were the requirements to get a free one?


If you had an active order to purchase BTC at the time of the breach..  you are eligible.



where do you request for one?

You can not roll a BitCoin, but you can rollback some. Cheesy
Roll me back: 1NxMkvbYn8o7kKCWPsnWR4FDvH7L9TJqGG
Jack of Diamonds
Sr. Member
****
Offline Offline

Activity: 252
Merit: 251



View Profile
July 16, 2011, 09:28:14 PM
 #10

What were the requirements to get a free one?


If you had an active order to purchase BTC at the time of the breach..  you are eligible.



where do you request for one?

Just click on 'Order a Yubikey', on the checkout page it will say the
price is free if you had a trade open when the site crashed.

If it doesn't show 'free' as the price but you really had a trade cancelled, email Mt. Gox and they'll send you one

1f3gHNoBodYw1LLs3ndY0UanYB1tC0lnsBec4USeYoU9AREaCH34PBeGgAR67fx
Spacy
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
August 01, 2011, 08:58:16 AM
 #11

How can I activate the Yubikey on the MtGox website?
julz
Legendary
*
Offline Offline

Activity: 1092
Merit: 1001



View Profile
August 01, 2011, 09:01:12 AM
 #12

How can I activate the Yubikey on the MtGox website?

Just login and use it.  After the first use - it'll be required next time.

You only need to give the pad a very short press for it to spit out it's stuff.

oh.. and make sure the key is the right way up in the USB port.. if you're not used to those flat keys, it's kind of ambiguous Tongue

@electricwings   BM-GtyD5exuDJ2kvEbr41XchkC8x9hPxdFd
Spacy
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
August 01, 2011, 09:06:28 AM
 #13

How can I activate the Yubikey on the MtGox website?

Just login and use it.  After the first use - it'll be required next time.

You only need to give the pad a very short press for it to spit out it's stuff.

oh.. and make sure the key is the right way up in the USB port.. if you're not used to those flat keys, it's kind of ambiguous Tongue

Thx, I did that. After the code is entered, I get logged out again, and I still can login withouth the Yubikey. I think I have to contact Mtgox support Smiley Thx for the help.
julz
Legendary
*
Offline Offline

Activity: 1092
Merit: 1001



View Profile
August 01, 2011, 09:15:12 AM
 #14

Thx, I did that. After the code is entered, I get logged out again, and I still can login withouth the Yubikey. I think I have to contact Mtgox support Smiley Thx for the help.

That happened to me when I touched the pad too long. Have you tried a really short tap?

@electricwings   BM-GtyD5exuDJ2kvEbr41XchkC8x9hPxdFd
Spacy
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
August 01, 2011, 10:31:26 AM
 #15

Thx, I did that. After the code is entered, I get logged out again, and I still can login withouth the Yubikey. I think I have to contact Mtgox support Smiley Thx for the help.

That happened to me when I touched the pad too long. Have you tried a really short tap?


Ah, thank you very much, now it works. When I pressed too short, no code was entered, so I pressed a "little bit" longer ;-)
MagicalTux
VIP
Hero Member
*
Offline Offline

Activity: 608
Merit: 501


-


View Profile
August 01, 2011, 10:57:59 AM
 #16

Thx, I did that. After the code is entered, I get logged out again, and I still can login withouth the Yubikey. I think I have to contact Mtgox support Smiley Thx for the help.

That happened to me when I touched the pad too long. Have you tried a really short tap?


Ah, thank you very much, now it works. When I pressed too short, no code was entered, so I pressed a "little bit" longer ;-)

Yep, timing can be tricky, we'll add some explanations.
elggawf
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
August 01, 2011, 02:43:31 PM
 #17

I got mine a while back, forgot to mention it. I'd thought I had trades open at the time, but when I visited the Yubikey page while logged in it kept asking for $29.99. MT straightened that out though, and I received it quite quickly from Japan.

Yep, timing can be tricky, we'll add some explanations.

My only issue with it has been the withdrawal press: 3s seems way too long and the key won't do anything. To log in, I do a fast-touch and don't even count. To withdraw, anything longer than "one mississippi" and it won't do anything, but about 1 second press works for withdrawals.

^_^
falkenberg
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
August 09, 2011, 02:14:07 PM
 #18

Negative side, it's bound to Mt. Gox so you can't use it as a normal YK on any other site.

Did you try it on http://demo.yubico.com/php-yubico/one_factor.php ?
It is pitty if the key cannot be used outside MtGox (yes, I've read their EULA Smiley AFAIK yubikey has 2 slots for secret key, they can be switched by long tap. I wonder why they removed Yubiko key instead of using the second slot. If they would leave Yubico's secret key then the key could be used on other sites for authentication...
error
Hero Member
*****
Offline Offline

Activity: 588
Merit: 500



View Profile
August 09, 2011, 06:37:59 PM
 #19

Negative side, it's bound to Mt. Gox so you can't use it as a normal YK on any other site.

Did you try it on http://demo.yubico.com/php-yubico/one_factor.php ?
It is pitty if the key cannot be used outside MtGox (yes, I've read their EULA Smiley AFAIK yubikey has 2 slots for secret key, they can be switched by long tap. I wonder why they removed Yubiko key instead of using the second slot. If they would leave Yubico's secret key then the key could be used on other sites for authentication...

I was under the impression that MtGox used both keys.

3KzNGwzRZ6SimWuFAgh4TnXzHpruHMZmV8
falkenberg
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
August 09, 2011, 06:54:12 PM
 #20

I was under the impression that MtGox used both keys.

After reading the forum I came to the same conclusion. But why? What's the reason to allocate both slots if just one is needed for OTP? Even if they do not want to share secret keys with Yubiko (but I would trust them more then mtgox: they never loose their database while mtgox was hacked because someone steel the database. What will it be if the database with secret keys will be stolen next time?), they need just one slot.
cepler
Newbie
*
Offline Offline

Activity: 46
Merit: 0


View Profile
August 09, 2011, 07:16:40 PM
 #21

Negative side, it's bound to Mt. Gox so you can't use it as a normal YK on any other site.

Did you try it on http://demo.yubico.com/php-yubico/one_factor.php ?
It is pitty if the key cannot be used outside MtGox (yes, I've read their EULA Smiley AFAIK yubikey has 2 slots for secret key, they can be switched by long tap. I wonder why they removed Yubiko key instead of using the second slot. If they would leave Yubico's secret key then the key could be used on other sites for authentication...

I was under the impression that MtGox used both keys.

Download the personalization tool and take a peek at it:

http://www.yubico.com/personalization-tool

I have two Yubikeys on the way for password database use (ie: Passpack.com, Lastpass.com, 1Password, etc) and have been reading up on them.  Going to try to get the wife to use one... *crosses fingers*
falkenberg
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
August 09, 2011, 07:34:07 PM
 #22

Download the personalization tool and take a peek at it:

If I understood it well, with this tool you can change secret AES key, but you need one from Yubiko in case if you want to be authenticated by on-line services.  Yubiko's keys are stored in the moment of creation. If mtgox overrides it then you do not have the valid key Sad
elggawf
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
August 09, 2011, 09:28:33 PM
 #23

If I understood it well, with this tool you can change secret AES key, but you need one from Yubiko in case if you want to be authenticated by on-line services.  Yubiko's keys are stored in the moment of creation. If mtgox overrides it then you do not have the valid key Sad

If I understood it well, if you blow away your AES key on your Yubikey, then you'd have to convince MtGox to let you update the AES key on their site before you could keep using it with them. Chances are they're not going to want to do that - they'd rather just charge you $30 and send you another key.

^_^
Maged
Legendary
*
Offline Offline

Activity: 1204
Merit: 1015


View Profile
August 10, 2011, 03:07:01 AM
 #24

I was under the impression that MtGox used both keys.

After reading the forum I came to the same conclusion. But why? What's the reason to allocate both slots if just one is needed for OTP? Even if they do not want to share secret keys with Yubiko (but I would trust them more then mtgox: they never loose their database while mtgox was hacked because someone steel the database. What will it be if the database with secret keys will be stolen next time?), they need just one slot.
It's so that if you are man-in-the-middled, the worst someone could do is log in and trade. They wouldn't be able to withdraw, even if they had you pregenerate a bunch of OTPs for login.

cepler
Newbie
*
Offline Offline

Activity: 46
Merit: 0


View Profile
August 10, 2011, 04:02:27 AM
 #25

There's no technical reason for Mt. Gox to lock the second profile.  If they left it open then you could use it for whatever you wanted, static password, Challenge-Response, a Yubico OTP, whatever but nope, they decided to lock it in to Mt. Gox only.  I suppose an argument could be made that it makes it so that if you hold the button down past the first profile's time it'll activate the second and still get you in but that's about it.  Hopefully they'll just give out the key soon so people can take advantage of the other profile, especially since they're paying a premium for a pre-configured one.  (Ya I know, labor to configure/ship etc them)
geek-trader (OP)
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


View Profile
August 10, 2011, 04:08:01 AM
 #26

There's no technical reason for Mt. Gox to lock the second profile.  If they left it open then you could use it for whatever you wanted, static password, Challenge-Response, a Yubico OTP, whatever but nope, they decided to lock it in to Mt. Gox only.  I suppose an argument could be made that it makes it so that if you hold the button down past the first profile's time it'll activate the second and still get you in but that's about it.  Hopefully they'll just give out the key soon so people can take advantage of the other profile, especially since they're paying a premium for a pre-configured one.  (Ya I know, labor to configure/ship etc them)

Tell me if I have this right:  A Yubikey has 2 "profiles" -  a short press and a long press.

If this is correct, then MtGox is using them both.  A short press to login, and long press to withdraw funds.

Make 1 deposit and earn BTC for life! http://bitcoinpyramid.com/r/345
Play my FREE HTML5 games at: http://magigames.org  BTC donations accepted.
elggawf
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
August 10, 2011, 04:44:41 AM
 #27

Tell me if I have this right:  A Yubikey has 2 "profiles" -  a short press and a long press.

If this is correct, then MtGox is using them both.  A short press to login, and long press to withdraw funds.

Yes.

^_^
forbun
Member
**
Offline Offline

Activity: 107
Merit: 10


View Profile WWW
August 30, 2011, 09:09:37 PM
 #28

Why bother-- How does using separate profiles for login and withdrawal add security?


Also, on https://yubikey.mtgox.com/ why does the top of the page say: Last Price: 0.53910961 High:0.53910961 Low: 0.53910961 Volume: 0

What name would you give to the smallest unit of bitcoin (0.00000001)? sat. What name would you give to 100 sats? bit. 1 bit = 1 uBTC. 1,000,000 bits = 1 BTC. It's bits
elggawf
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
August 30, 2011, 10:06:22 PM
 #29

Why bother-- How does using separate profiles for login and withdrawal add security?

Only thing I can think of? It solves MITM attacks accidentally allowing withdrawals.

If you MITM someone, get a login session to MtGox, you can't just "oops you're logged out" the client end in order to get another yubikey code to let you withdraw... because that would be a login code not a withdraw code. In order to actually steal from someone, you have to MITM the login session and the withdraw request, replacing the withdraw request with your own information.

It's not a huge leap of security, but it ups the bar a bit (because the user has to want to create a withdrawal while the attack is going on).

^_^
Pages: 1 2 [All]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!