TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The Yubikey Is the Digital Seatbelt We Need

45 pointsby mzagaja9 months ago

13 comments

v1ne9 months ago
No, it&#x27;s not. We need less shoddy practices to develop software, e.g. mandatory 4-eyes process for security-critical changes, thread modelling, and maybe more Hardware Security Modules that encrypt critical information.<p>And if you need a second factor, I&#x27;m sure any smartphone-based TOTP will do. People already guard their smartphone well. No extra key fob needed.
评论 #41432335 未加载
评论 #41433418 未加载
评论 #41433685 未加载
评论 #41433966 未加载
评论 #41433522 未加载
评论 #41433651 未加载
评论 #41434394 未加载
评论 #41434049 未加载
评论 #41433584 未加载
coldblues9 months ago
Yubikeys are useless when someone can reset your password or 2FA using personally identifiable information that was just leaked. A lot of us who practice good security will be PWNED through large scale data leaks. Whenever I sign up, I sign up with fake information, and so should you. Most services will not KYC you, so just lie.
评论 #41433870 未加载
评论 #41438515 未加载
Yizahi9 months ago
Bought yubikey on a sale a few years ago. Not usable for mobile in that model (4?) (but I knew it in advance of course). Then found out that most of the sites don&#x27;t accept it in the Firefox, only in the Chrome and its clones. And so it is collecting dust somewhere in my old apartment.
评论 #41544838 未加载
评论 #41438525 未加载
评论 #41434343 未加载
tcsenpai9 months ago
The fact that there are other ways to circumvent 2fa highly depends on companies practices. Using fake informations is a good start but even without fake infos I still am trying to regain access to the majority of my 2faed accounts since last December
Chengkurt129 months ago
BEST AGENCY TO RECOVER LOST OR STOLEN CRYPTOCURRENCY<p>I recommend Hack Recovery KEVIN M HACKER to anyone who needs this service. I decided to get into crypto investing and lost my crypto to an investor late last year. The guy who was supposed to manage my account was a fraud the whole time. I invested $180,000 and at first my read and profit margins looked good. I got worried when I couldn&#x27;t make withdrawals and realized I had been tricked. I found some testimonials that people had to say about Hack Recovery KEVIN M HACKER and how helpful it was in getting their money back. I immediately contacted him via. Email: kevinmitnick100@hackermail.com, Telegram @Kelvinmhacker or WhatsApp via: +1-256-956-4498, and I’m sure you will be happy you did.
merkle9 months ago
The YubiKey is not the single answer for this problem. The right approach will depend on the specific needs of each user.<p>More importantly, MFA needs to be more widely adopted and the account recovery process needs to be hardened.
ChrisArchitect9 months ago
Related:<p><i>EUCLEAK Side-Channel Attack on the YubiKey 5 Series</i><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=41434500">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=41434500</a>
评论 #41438507 未加载
rcarmo9 months ago
Nope. It’s an add-on, but you can lose them. I am a bit flabbergasted that corporates are now handing them out like candy, but only one to a user. And if they lose them, they can’t even log in to request another.
评论 #41433621 未加载
评论 #41438538 未加载
评论 #41435660 未加载
stuaxo9 months ago
I did have one, it was something like 20 steps to get it setup - a bit of a pain.
评论 #41433599 未加载
jen729w9 months ago
Yubikey will never prevent your data from being leaked. They didn’t crack your password.<p>But a random, unique password prevents further harm. They can’t get data from another site just because they hacked this one.<p>Have random, unique passwords. Use a password manager. Done.
评论 #41434023 未加载
评论 #41433780 未加载
评论 #41433603 未加载
darkhorn9 months ago
I prefer user side SSL certificates.
评论 #41433652 未加载
评论 #41443509 未加载
nxobject9 months ago
An even better analogy would be food safety enforcement for large food processors: not wearing a seatbelt makes the author’s proposal seem like it’s about you, when it really is about well-needed criminal penalties for FooCoGotPwned Ops (where FooCoGotPwned isn’t in tech, health, or finance.) Otherwise, like listeria in your liverwurst, it’s only a matter of time until you get hacked.<p>The only current remedy is a class action lawsuit which will eventually give you a pittance after many years, and it’s pathetic.
ementally9 months ago
<a href="https:&#x2F;&#x2F;ninjalab.io&#x2F;eucleak&#x2F;" rel="nofollow">https:&#x2F;&#x2F;ninjalab.io&#x2F;eucleak&#x2F;</a> the timing lol<p>Extraction of the ECDSA secret key of Yubikey 5 series FIDO devices