2FA USB security sticks

Author
Discussion

JABB

Original Poster:

3,589 posts

242 months

Wednesday 5th April 2023
quotequote all
Does anyone use any of the USB 2FA sticks? They seem a good idea to me but the PH massive is more knowledgable on such things

Harpoon

1,945 posts

220 months

Wednesday 5th April 2023
quotequote all
Do you mean something like a Yubikey?

https://www.yubico.com/products/yubikey-5-overview...

JABB

Original Poster:

3,589 posts

242 months

Wednesday 5th April 2023
quotequote all
Harpoon said:
Do you mean something like a Yubikey?

https://www.yubico.com/products/yubikey-5-overview...
Yes, or the alternatives.
Google do one. Solokey another


Your Dad

1,995 posts

189 months

Thursday 6th April 2023
quotequote all
I use Yubikey where a soft token can't be used.

Glade

4,305 posts

229 months

Thursday 6th April 2023
quotequote all
I have two Yubikey. One on my home PC, one on my keyring.

About a year ago I had a spate of various accounts having login attempts. So ingot these keys and 1password and set up strong passwords for everything.

If I want to log into certain accounts on a new device I need to insert and touch one of they keys when requested, or use NFC to authenticate contactlessly. It's fairly faff-free.

The one at home is a mini USB-C that you can hardly notice, I just reach down and touch it, the one on my keyring is NFC and USB-C for phones work laptop etc.

I find it quite unobtrusive. Actually, I don't need to use them very often once the device has been authenticated initially. Just if you get a new phone or work laptop etc. It would be a problem if I tried to log in on my parents PC for example as they only have USB-A... But most new kit has USB-C now.

It's fairly seamless but It's a leap of faith to set your accounts to only require the security key. This is why they reccomend enabling 2 keys incase you loose one.

I had to get my head around how to set up the keys and 1password app on all my devices, and the browser extensions in browsers I used, including importing passwords from chrome to 1password.

Then another leap of faith to delete all the stored passwords in various places e.g. chrome built in password manager etc and hand it over to the 1password extensions etc.

Then I used the "watchtower" in 1password to show all the duplicated or insecure passwords and work through them all generating unique strong passwords. (I didn't in my paternity while mum and baby were sleeping).

Edited by Glade on Thursday 6th April 08:15

Glade

4,305 posts

229 months

Thursday 6th April 2023
quotequote all
Then finally I had several authenticator apps, well you can set up 1password as your authenticator app, and mostly this is all I use and mostly it is quite slick.

therams

261 posts

191 months

Thursday 6th April 2023
quotequote all
Yubikey seems to be the device of choice in my industry

SBDJ

1,324 posts

210 months

Thursday 6th April 2023
quotequote all
We issue a Yubikey 5 to everyone at work who needs access to certain systems, including any VPN use.

I like it as a solution - using webauthn as either a passwordless authentication method or as an additional factor works well, and I can use the PKCS#11 store to store SSH keys securely too.

JABB

Original Poster:

3,589 posts

242 months

Friday 7th April 2023
quotequote all
Sounds like a positive then. I have been having one or two issues and started to use 2FA more. I like the idea of these

Paper Lawyer

248 posts

235 months

Friday 7th April 2023
quotequote all
I similarly have a yubikey on my keyring and a back up yubikey sat at home. Less faff than the hassle of transferring codes to replacement mobiles.