geek-trader (OP)
|
|
July 16, 2011, 06:19:16 AM |
|
It's little, the "up" side (when plugged into my MacBook Pro) has a small copper circle that you press.
When logging in you press it for 1/2 second. When you release, it sends a string of text to the MtGox "Yubikey" input field.
I have not done a withdrawal yet, but my understanding is that you press it for 3 seconds (instead 1/2 a second), and it sends a different string.
When you first plug it in, OS X thinks it's a keyboard, but you can just cancel out of that, and it works fine.
With this, I'm confidant that my MtGox account is safe from hackers. Is my MtGox account safe from MtGox? I don't know, but they have all the volume, so they have me for now.
|
|
|
|
rate5
Member
Offline
Activity: 104
Merit: 100
|
|
July 16, 2011, 10:46:02 AM |
|
Glad to hear you got your free Yubikey from mtgox. They look cool I am thinking of buying one.
|
|
|
|
RyanWebber
Member
Offline
Activity: 84
Merit: 10
|
|
July 16, 2011, 11:01:51 AM |
|
Definately worth having if you're involved in high volume trading there. I'll probally buy one soon cause I'm pretty paranoid after the previous cluster §$%¤
|
If I have been remotely useful feel free to donate: 1DgkA1S64CoVGu1q5JFSz4maRQJYw2dMC8
|
|
|
elggawf
|
|
July 16, 2011, 12:59:03 PM |
|
What were the requirements to get a free one?
|
^_^
|
|
|
RchGrav
|
|
July 16, 2011, 05:40:16 PM |
|
What were the requirements to get a free one?
If you had an active order to purchase BTC at the time of the breach.. you are eligible.
|
4C 6F 6E 67 4C 69 76 65 42 69 74 63 6F 69 6E Qba'g lbh unir nalguvat orggre gb qb?
|
|
|
geek-trader (OP)
|
|
July 16, 2011, 06:51:15 PM |
|
What were the requirements to get a free one?
I had a trade nullified by the rollback after the hack.
|
|
|
|
Jack of Diamonds
|
|
July 16, 2011, 07:02:27 PM |
|
I also got a free one a while back, have to say I can really sleep at ease now even with significant $$ or BTC stored in the account.
Spent time researching how feasible it is to crack Yubikey authentication, seems to be very infeasible so I trust it for now.
Negative side, it's bound to Mt. Gox so you can't use it as a normal YK on any other site.
|
1f3gHNoBodYw1LLs3ndY0UanYB1tC0lnsBec4USeYoU9AREaCH34PBeGgAR67fx
|
|
|
RchGrav
|
|
July 16, 2011, 07:28:41 PM |
|
I also got a free one a while back, have to say I can really sleep at ease now even with significant $$ or BTC stored in the account.
Spent time researching how feasible it is to crack Yubikey authentication, seems to be very infeasible so I trust it for now.
Negative side, it's bound to Mt. Gox so you can't use it as a normal YK on any other site.
Not really that negative from a security standpoint.. I have evaluated the Yubikey solution and can confirm that a higher degree of both security and functionality is possible when it is used in a site specific fashion.
|
4C 6F 6E 67 4C 69 76 65 42 69 74 63 6F 69 6E Qba'g lbh unir nalguvat orggre gb qb?
|
|
|
d.james
Sr. Member
Offline
Activity: 280
Merit: 250
Firstbits: 12pqwk
|
|
July 16, 2011, 09:22:05 PM |
|
What were the requirements to get a free one?
If you had an active order to purchase BTC at the time of the breach.. you are eligible. where do you request for one?
|
You can not roll a BitCoin, but you can rollback some. Roll me back: 1NxMkvbYn8o7kKCWPsnWR4FDvH7L9TJqGG
|
|
|
Jack of Diamonds
|
|
July 16, 2011, 09:28:14 PM |
|
What were the requirements to get a free one?
If you had an active order to purchase BTC at the time of the breach.. you are eligible. where do you request for one? Just click on 'Order a Yubikey', on the checkout page it will say the price is free if you had a trade open when the site crashed. If it doesn't show 'free' as the price but you really had a trade cancelled, email Mt. Gox and they'll send you one
|
1f3gHNoBodYw1LLs3ndY0UanYB1tC0lnsBec4USeYoU9AREaCH34PBeGgAR67fx
|
|
|
Spacy
|
|
August 01, 2011, 08:58:16 AM |
|
How can I activate the Yubikey on the MtGox website?
|
|
|
|
julz
Legendary
Offline
Activity: 1092
Merit: 1001
|
|
August 01, 2011, 09:01:12 AM |
|
How can I activate the Yubikey on the MtGox website?
Just login and use it. After the first use - it'll be required next time. You only need to give the pad a very short press for it to spit out it's stuff. oh.. and make sure the key is the right way up in the USB port.. if you're not used to those flat keys, it's kind of ambiguous
|
@electricwings BM-GtyD5exuDJ2kvEbr41XchkC8x9hPxdFd
|
|
|
Spacy
|
|
August 01, 2011, 09:06:28 AM |
|
How can I activate the Yubikey on the MtGox website?
Just login and use it. After the first use - it'll be required next time. You only need to give the pad a very short press for it to spit out it's stuff. oh.. and make sure the key is the right way up in the USB port.. if you're not used to those flat keys, it's kind of ambiguous Thx, I did that. After the code is entered, I get logged out again, and I still can login withouth the Yubikey. I think I have to contact Mtgox support Thx for the help.
|
|
|
|
julz
Legendary
Offline
Activity: 1092
Merit: 1001
|
|
August 01, 2011, 09:15:12 AM |
|
Thx, I did that. After the code is entered, I get logged out again, and I still can login withouth the Yubikey. I think I have to contact Mtgox support Thx for the help. That happened to me when I touched the pad too long. Have you tried a really short tap?
|
@electricwings BM-GtyD5exuDJ2kvEbr41XchkC8x9hPxdFd
|
|
|
Spacy
|
|
August 01, 2011, 10:31:26 AM |
|
Thx, I did that. After the code is entered, I get logged out again, and I still can login withouth the Yubikey. I think I have to contact Mtgox support Thx for the help. That happened to me when I touched the pad too long. Have you tried a really short tap? Ah, thank you very much, now it works. When I pressed too short, no code was entered, so I pressed a "little bit" longer ;-)
|
|
|
|
MagicalTux
VIP
Hero Member
Offline
Activity: 608
Merit: 501
-
|
|
August 01, 2011, 10:57:59 AM |
|
Thx, I did that. After the code is entered, I get logged out again, and I still can login withouth the Yubikey. I think I have to contact Mtgox support Thx for the help. That happened to me when I touched the pad too long. Have you tried a really short tap? Ah, thank you very much, now it works. When I pressed too short, no code was entered, so I pressed a "little bit" longer ;-) Yep, timing can be tricky, we'll add some explanations.
|
|
|
|
elggawf
|
|
August 01, 2011, 02:43:31 PM |
|
I got mine a while back, forgot to mention it. I'd thought I had trades open at the time, but when I visited the Yubikey page while logged in it kept asking for $29.99. MT straightened that out though, and I received it quite quickly from Japan. Yep, timing can be tricky, we'll add some explanations.
My only issue with it has been the withdrawal press: 3s seems way too long and the key won't do anything. To log in, I do a fast-touch and don't even count. To withdraw, anything longer than "one mississippi" and it won't do anything, but about 1 second press works for withdrawals.
|
^_^
|
|
|
falkenberg
Member
Offline
Activity: 84
Merit: 10
|
|
August 09, 2011, 02:14:07 PM |
|
Negative side, it's bound to Mt. Gox so you can't use it as a normal YK on any other site.
Did you try it on http://demo.yubico.com/php-yubico/one_factor.php ? It is pitty if the key cannot be used outside MtGox (yes, I've read their EULA AFAIK yubikey has 2 slots for secret key, they can be switched by long tap. I wonder why they removed Yubiko key instead of using the second slot. If they would leave Yubico's secret key then the key could be used on other sites for authentication...
|
|
|
|
error
|
|
August 09, 2011, 06:37:59 PM |
|
Negative side, it's bound to Mt. Gox so you can't use it as a normal YK on any other site.
Did you try it on http://demo.yubico.com/php-yubico/one_factor.php ? It is pitty if the key cannot be used outside MtGox (yes, I've read their EULA AFAIK yubikey has 2 slots for secret key, they can be switched by long tap. I wonder why they removed Yubiko key instead of using the second slot. If they would leave Yubico's secret key then the key could be used on other sites for authentication... I was under the impression that MtGox used both keys.
|
3KzNGwzRZ6SimWuFAgh4TnXzHpruHMZmV8
|
|
|
falkenberg
Member
Offline
Activity: 84
Merit: 10
|
|
August 09, 2011, 06:54:12 PM |
|
I was under the impression that MtGox used both keys.
After reading the forum I came to the same conclusion. But why? What's the reason to allocate both slots if just one is needed for OTP? Even if they do not want to share secret keys with Yubiko (but I would trust them more then mtgox: they never loose their database while mtgox was hacked because someone steel the database. What will it be if the database with secret keys will be stolen next time?), they need just one slot.
|
|
|
|
|