Тёмный

Passkeys On A Yubikey ? Here's How To Set Them Up 

MrTimTech
Подписаться 1,9 тыс.
Просмотров 8 тыс.
50% 1

Passkeys On A Yubikey ? Here's How To Set Them Up
In this video I am going to explain and show you how to use Passkeys and store them securely on any of your Yubikey 5 series.
In this video I am going to setup a passkey to access my Google Account as an example.
All Yubikey 5 series can store up to 25 Passkeys within the FIDO2/WebAuthn section of the Yubikey.
In the video I explain that you will need the Yubico Authenticator application, here's the direct link to the Yubico website where you can download the Yubico Authenticator if you don't already have it downloaded:
www.yubico.com/products/yubic...
Chapters
00:00 Intro
00:11 Things to know before setting up passkey
02:10 Installing the Yubico Authenticator application
06:13 Adding a Passkey login to my Yubikey and Google Account
10:16 Adding a backup Yubikey & Passkey to Google Account
11:29 A bit about deleting Passkeys
12:45 Testing logging in to Google with Passkey
15:19 Outro
Join this channel to get access to perks:
/ @mrtimtech2022
#passkeys
#yubikey
#google
#passkey

Наука

Опубликовано:

 

29 июл 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 27   
@tomg4260
@tomg4260 19 дней назад
Thanks for the video, no complaints on that. If anyone is thinking of getting these, forget it. Hard to set up and even harder to get them to work on the things you want to protect. If this was a good product it would be plug and play, this key is simply a good idea wrapped in a terrible product. I've seen 10 videos now and can't get this to work with any websites.
@ritagraham6703
@ritagraham6703 24 дня назад
Thanks, Tim. I have been trying to install my YubiKeys for 2 weeks unsuccessfully. Your instructions have been the easiest to understand. Thanks!
@MrTimTech2022
@MrTimTech2022 24 дня назад
@ritagraham6703 - Oh wow, so pleased you found my solution and that it's worked for you too. Thanks for the feedback😁
@ritagraham6703
@ritagraham6703 24 дня назад
@@MrTimTech2022 I haven’t implemented your instructions but will do so soon. 🙏
@markembling
@markembling 2 месяца назад
Very clear walkthrough and demonstration of the process. Thanks for making the video. However, having seen the process from start to finish like that, I'm struggling with one thing: yes, it might be a very secure process from a remote attack point of view but it's surely weaker in terms of a local/physical attack. Using a Yubikey (or similar) security key as a second factor, an attacker would need the following to gain access to your account: 1. Your username (let's assume this is well known or at least very easily guessable; not a secret at all). 2. Your password (obviously the strength of this depends on the actual password in use, but hopefully it's at least reasonably good). 3. Your second factor. When using a physical key like this, my understanding is that it's as secure as a passkey insofar as nobody is likely to be able to compromise it remotely. So they'd need the actual key itself as well. However, using a passkey, they'd only need 1 and 3. They'd also need the PIN for the key but having watched your video, I assume that's just a basic numeric key (you used six digits). Not nearly as strong as whatever your actual Google account password would have been. So surely now your account is only as secure as your Yubikey is. If you drop it, lose it, leave it unattended on your desk in the office accidentally, get mugged, whatever it might be... you have given up a very large proportion of the protection on your account and you'd need to get into your account and revoke the passkey ASAP. Whereas in the same scenario using the key as a second factor, you'd still be relatively well protected by your actual account password giving you a little more breathing space to get logged in and revoking the second factor for the now-lost-or-stolen Yubikey. Everyone keeps talking about how passkeys are the best of the best security-wise, so I wonder if I'm somehow missing something?
@MrTimTech2022
@MrTimTech2022 2 месяца назад
I see where you're coming from and I think it needs some more investigation in to that to be honest. I like everyone am still quite new to Passkeys and I'm still I have to say using the older methods for logging in to accounts, although I do have a few passkey ones but not many. I think I will wait to see what happens with other web providers and how quickly they all move over to Passkeys - if they do. Before I am totally convinced, like yourself I guess ?
@stevehunt2125
@stevehunt2125 2 месяца назад
Excellent video thanks
@MrTimTech2022
@MrTimTech2022 2 месяца назад
You're very welcome Steve 👍
@ripleysmith7583
@ripleysmith7583 Месяц назад
Great thanks
@MrTimTech2022
@MrTimTech2022 Месяц назад
No problem, you're welcome 👍
@ecu4321
@ecu4321 5 месяцев назад
i've used a yubico Security Key NFC and was able to use FIDO2 Passkeys. I think it's not tied only to the 5 series.
@MrTimTech2022
@MrTimTech2022 5 месяцев назад
@ecu4321 - Thanks for your comment, yes you're correct in that the Security Keys do support FIDO2 Passkeys. I will be doing a video soon about selecting keys.
@the_analogist
@the_analogist Месяц назад
Is the pin you entered when setting up the passkey is the pin/pass phrase for the yubikey or a pin per passkey. I assume the former.
@MrTimTech2022
@MrTimTech2022 Месяц назад
Hi there, the pin is the pin for the Yubikey itself and not a pin for the passkey(s). So the pin is tied to accessing the yubikey. Hope that makes sense, so yes the former per your question.
@maledven2622
@maledven2622 4 месяца назад
Great Video! Thx.
@MrTimTech2022
@MrTimTech2022 4 месяца назад
Thanks @maledven2622 - You're most welcome, glad you found it helpful😀
@IssacBerry-nd8pt
@IssacBerry-nd8pt 2 месяца назад
i bought a series 5 and only seldom use. how the hell google make it into a passkey? and limit to 25/key? before that i think i could link unlimited accounts. why go backward?
@MrTimTech2022
@MrTimTech2022 2 месяца назад
True, it's just a personal choice in the end really. I just prefer some physical device to store keys/authentication rather than storing things in the cloud. I am also waiting until most of my accounts use PassKeys before I totally go over to them for logins.
@x91w
@x91w 2 месяца назад
Token2 stores 300 passkeys
@MrTimTech2022
@MrTimTech2022 2 месяца назад
Really, that's better then, although according to what I researched on the Yubico website it can only stores 25 individual keys, google search reveals this too. Do you have a link for your info ?
@IssacBerry-nd8pt
@IssacBerry-nd8pt 2 месяца назад
no sh1t, not working for me. cant finish the process.
@IssacBerry-nd8pt
@IssacBerry-nd8pt 2 месяца назад
ok, i can add my yubico keys as passkeys in android phone. but not the win10+chrome
@MrTimTech2022
@MrTimTech2022 2 месяца назад
@@IssacBerry-nd8pt I presume you are using the same email accounts for the passkeys on all 3 devices. I would check the Yubico support pages.
@IssacBerry-nd8pt
@IssacBerry-nd8pt 2 месяца назад
@@MrTimTech2022 i sorted out... i have to directly run the portable chrome and NOT thru sandbox. solved thx
@MrTimTech2022
@MrTimTech2022 2 месяца назад
@@IssacBerry-nd8pt Oh right, that's way because of running a VM. I didn't realise you were running a VM. Anyway at least you've resolved the issue now, great work!
Далее
Which YubiKey To Buy
18:55
Просмотров 2,1 тыс.
Debunking 5 MYTHS About Yubikey
15:36
Просмотров 190 тыс.
Connect2 Coordinator High-Level Demo
12:37
You Should Be Using Yubikeys!
34:34
Просмотров 791 тыс.
Passwords vs. Passkeys - FIDO Bites Back!
11:05
Просмотров 38 тыс.
YubiKey Complete Getting Started Guide!
51:19
Просмотров 164 тыс.
STOP Using Passwords!
17:19
Просмотров 29 тыс.
How to Soldering wire in Factory ?
0:10
Просмотров 5 млн
How to Soldering wire in Factory ?
0:10
Просмотров 5 млн
$1 vs $100,000 Slow Motion Camera!
0:44
Просмотров 28 млн