Тёмный

You Should Be Using Yubikeys! 

Crosstalk Solutions
Подписаться 435 тыс.
Просмотров 791 тыс.
50% 1

Наука

Опубликовано:

 

22 июл 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 1 тыс.   
@stevenhatcher6760
@stevenhatcher6760 3 года назад
Just ran across this video... All I can say is THANK YOU! You did an amazing job at laying out what Yubikeys not only are, but the demos were off the chain! Keep up the great work sir!
@APrintmaker
@APrintmaker 3 года назад
Very useful. I too had Yubikeys on hand waiting to understand how to use them. Multiple keys per account info helped alot.
@sdiggly
@sdiggly 3 года назад
Wow, great video! Extremely informative, very well edited. This was exactly what I needed, thank you!
@VirgilNicolae
@VirgilNicolae 3 года назад
Thanks, Chris! Using them already for about 3 years but managed to find some new things watching your video!
@CrosstalkSolutions
@CrosstalkSolutions 3 года назад
Great to hear!
@grantrettke4851
@grantrettke4851 2 года назад
Best balance between skimming over details to make it short and going way over time to make an exhaustive yet way too long video. Key points are covered. Points out of scope are stated as such. Points that have bigger implications and do need consideration at some point, are also made clear: things that make you think. Ideal balancing a critical yet confusing topic. Great vid.
@cbrunnkvist
@cbrunnkvist 3 года назад
"Scanning" the desktop screen by the desktop app is a pretty neat little usability hack! I haven't been using the app but now I'm sold on it 🤓
@obiwan300
@obiwan300 3 года назад
For your time codes to automatically put "chapters" on your timeline, you have to put a 0:00 time code in the list. Great video!
@betterwithrum
@betterwithrum Год назад
yeah at 25:30 I was like, 'this is really good, but I gotta go'
@HouseDyson
@HouseDyson 3 года назад
The acting for the google Authenticator is top notch lol. Great video!
@rexjuggler19
@rexjuggler19 3 года назад
We have company issued Yubikeys for over 5 years and you are exactly right about how good they are. Even though I'm a very long time user, I am so glad you made this video. I have actually been wanting to use Yubikeys for my personal accounts, but hadn't invested the time to figure out how to set it up. So I've been using the MS and Google authenticators. But I prefer the yuibikey for the same reasons you cited. I was working in Germany a couple years ago and forgot my yubikey at home and needed access to our corporate VPN. We fortunately had an office a couple hours away and I was able to get a replacement through our IT. But I wasn't sure if I could setup a couple so I'd have a backup. I also wasn't sure about how to get it to work with a phone since my company issued yubikey is the USB A style. You really answered ALL my questions. I'm going to hit your link and pick up a few.
@rexjuggler19
@rexjuggler19 3 года назад
Yes, I am replying to my own post. I just received the 2x5NFC USB A's today that I ordered. I am even more positive now than before that this is what I needed as I spent a time over the weekend looking at the key capabilties. I am buying another 2 of them. I am getting a set for my wife for her to use for her accounts. As with most people, her security awareness is limited and it is pointless to preach about it to people. You just need to provide them with something secure and simple which this really does. It also means I can authorize all 4 on joint accounts so that if something happens to me she will have access to our accounts like gmail, 401k, banking etc. I work on numerous linux systems via putty and ssh and was very pleased I can use putty-cac as well even if the PC doesn't have a SmartCard slot. I tried it out earlier today on a few systems and works great. I had looked into SmartCard as an option about a year ago as a personal security solution, and dismissed it due to not working with phone and needing a reader among other shot-comings. I do use a CAC SmartCard for work, but only have the reader on my company issued laptop. This yubikey solves so many problems. I didn't know it had so many authentication choices. However, BEWARE - You need to get at least 2 and make sure you setup the additional keys or you WILL be locked out of your account if something happens to your main key. That should be made clear to someone considering this.
@wifienabled
@wifienabled Год назад
​@@rexjuggler19 there are recovery codes in the event u lose your physical keys
@carlode3593
@carlode3593 3 года назад
Thank you for your thorough summary of Yubikeys and set up. Bravo!!
@contextmatters8243
@contextmatters8243 2 года назад
Excellent! I just got the 5 NFC and answered EVERY question I had (spent hours trying to connect the dots)... Thanks a bunch!
@Mopki3
@Mopki3 3 года назад
I purchased 5 NFC and 5C NFC. I'm ready to set them up now that I lost my job. I wish I found you before and used your link. Great video!
@mikeoreilly4020
@mikeoreilly4020 3 года назад
I've always found Ubikey's own documentation to be fairly obtuse. Thanks for the clearest explanation yet.
@gsawnv
@gsawnv 3 года назад
Love the 568B artwork on your wall.
@JimPeiffer
@JimPeiffer Год назад
Thanks Chris, great presentation. Have had a Yubikey for several years but only used it a few times so this was a great refresher.
@olafschermann1592
@olafschermann1592 3 года назад
Thank you for that great overview and answering all of my questions before i could even ask them.
@KrispyKrink
@KrispyKrink 3 года назад
Great video! I use the 5ci as primary and 5 NFC as secondary. I also have my PGP keys on my 5ci.
@mdkv4
@mdkv4 3 года назад
Funny, I just finished setting mine up last night! Ordered two more for my parents.
@bewarako
@bewarako 3 года назад
Great video! Been using these for quite sometime, make sure to get an extra as backup as mentioned!
@tadbarker7082
@tadbarker7082 3 года назад
I’m a tech moron.... and was filled with dread at having to update my entire online security & password collection over various macs. This video has really helped ! I think I can now master this with a bit of time. Thanks 🙏
@AmichaiRotman
@AmichaiRotman 2 года назад
You don't have to use the manual method to configure the same TOTP on all your YubiKeys, just switch between them while on the QR Code screen and enter the TOTP from the last key you configure to finish the respective service TOTP setup.
@RETRO-CONSOLE-GAMER
@RETRO-CONSOLE-GAMER 3 года назад
Chris U have converted me to this yubikey, Thanks i feel much safer now , great vid
@adamkee97
@adamkee97 3 года назад
Now, this is neat. I never know those accounts are stored in the keys. I started using Authy last year because it can back-up my keys. But that means my secret codes are now on the cloud. I need that feature so I won't lose them whenever I reset my phone, which I do every time when it gets a major system upgrade. I don't lose my stuff easily, so having a key is better than having an app. Thank you for such an informative video.
@iThinkergoiMac
@iThinkergoiMac 3 года назад
Great video! It's worth noting that for most accounts, even if you miss typing in the code before it expires, as long as you know it, you can still enter it for some time (usually between 5 and 15 minutes). Obviously, as soon as it expires you can't see it anymore, but if you still remember it, you can still enter it.
@wifienabled
@wifienabled Год назад
that's a hazard if u think about it
@paulrobertmarino7623
@paulrobertmarino7623 3 года назад
For TOTP you can use the QR code to program multiple Yubikeys simply program one and do not put the code from the key into the site, then insert your second one and add it there two and once you've programed the last one then enter the code into the site. As an alternative for having multiple keys for TOTP you may copy the code or QR image and store it in an encrypted file using tools like GPG/OpenPGP but that is an other subject, sort of... it would have been nice to cover the PGP functions of the Yubikey as well, may be that can be a future video :).
@ahensley
@ahensley Год назад
If you do this I don't believe you'd be able to revoke them individually, i.e. in case you lost one. You'd just have to remove and re-add the one you still have.
@MitchKarajohn
@MitchKarajohn Год назад
@@ahensley on the contrary, in that case if you lose one key you can just get a new one and feed it the existing TOTP seed (the original QR code/secret code). This way you don't have to invalidate existing TOTPs and redo them all over again in both new and old keys. (If there is a chance that you lost a key to someone who also has access to your passwords then the correct thing to do is actually invalidate existing TOTPs and redo them, not reuse existing seeds)
@Tinker_Thinker
@Tinker_Thinker 3 года назад
Logged into RU-vid with my YubiKey 5nfc usb-c to watch this video. Love YubiKeys and have a few, been using them since 2017.
@jordanlambuth362
@jordanlambuth362 3 года назад
This a great video I really enjoyed it and it was very informative. I got one of these that was left over from a project at work. To pilot for a new customers 2FA implementation, seems very kool. I'm going to try and use the PIV deployment method with local active directory and a CA to use them as a smart card.
@kensmith7417
@kensmith7417 3 года назад
Second Yubikey just got here, third is on the way, love them.
@cristalballena-hotel
@cristalballena-hotel 3 года назад
Great video, thank you for giving this profound overview.
@CrosstalkSolutions
@CrosstalkSolutions 3 года назад
Glad you enjoyed it!
@sugafreebree
@sugafreebree 2 года назад
Thank you so much, this vid is amazing. You answered every question I had about the different application types. Simply brilliant! I am so thankful for you and you sharing your time.
@terrancejhedrick
@terrancejhedrick 3 года назад
Thanks for the incredibly useful video! You demystified a lot of information in a clear way!
@mark_loveless
@mark_loveless 3 года назад
Nice! Yes more like this. Timely too, I cleaned out a desk drawer and found some unused Yubikeys, they are getting put into place pronto.
@AnimalFacts
@AnimalFacts 3 года назад
Where can I get that shirt? Need!
@domzzz1244
@domzzz1244 3 года назад
Same, LINK!!!!
@YadraVoat
@YadraVoat 3 года назад
I trust you recognize its from the Chromium browser's unreachable-location minigame? :-)
@cocotug0
@cocotug0 3 года назад
probably not online...
@ChrisHolt1
@ChrisHolt1 3 года назад
TEEPUBLIC has several designs. I like this one www.teepublic.com/t-shirt/2053315-chrome-t-rex-dinosaur-rawr
@itchytastyurr
@itchytastyurr 3 года назад
make a stencil out of lego and ink stamp it on....
@vorrac
@vorrac 2 года назад
Nice Video, I got a yubikey a few months ago but I wasn't using it to it's full potential, this video helped me understand what are the capabilities, thanks!
@daromee
@daromee 3 года назад
Yes I bought two and they have been lying on my desk for two years as I tried to use and got all mixed up so hopefully I will be able to understand how to use (haven't listened to your clip yet).
@mvl8209
@mvl8209 3 года назад
I was constantly thinking "something in the background looks familiar, but I can't pinpoint it... Then my eye fell on the frame hanging next to your youtube reward button thing, and it clicked :D
@mvl8209
@mvl8209 3 года назад
@fuck google It's a wiring diagram for Ethernet cables www.google.com/search?q=ethernet+wiring+diagram&sxsrf=ALeKk00UdIyMZp6J_v1JjfzmBKeHK0SxRQ:1606463841336&tbm=isch&source=iu&ictx=1&fir=d3PlvGVMrC5arM%252CV-i5CBR7Nb_OJM%252C_&vet=1&usg=AI4_-kSGgTtbv7cz3tvqafq7529zknD0IA&sa=X&ved=2ahUKEwj3vO2UoKLtAhWNmKQKHeGNA50Q9QF6BAgCEFU&biw=1536&bih=722#imgrc=d3PlvGVMrC5arM
@JCtheMusicMan_
@JCtheMusicMan_ 3 года назад
Is it recommended to buy two keys per user in an enterprise setting? Users are notorious for losing things 😅
@chrisumali9841
@chrisumali9841 3 года назад
Thanks for the demo and insight, have a great day
@d3m3tr3s
@d3m3tr3s 3 года назад
Chris, I love your videos and especially this one, I saw it maybe more than 10 times....and if you see the rest of the comments, I purchased two using your links. But l figured that yubikeys are NOT faster than any Authenticator app and let me tell you and prove you why: I spend a whole evening trying to setup my 2 yubikeys, a 5Ci that I will use as a backup (got the idea from you) and a 5C Nano for my laptop. Later on, I decide to go to bed as I had to wake up early next day. So while I’m on my bed and using my phone trying to fell asleep, I decide to check my unify network, by using the “Unifi Network” application but, it asked my for a 2 step authentication. Unifi was one of the first setups I did with Yubikey since I saw that also on your video. So the fact that I had to get up, go to the living room that I had my laptop and next to it my 5Ci yubikey, so I will put it on my phone, in order to login to Unifi Network app, make me realize that yubikeys are NOT faster than my Authy app which was still installed on my phone but without my Unifi auth, since I removed it once I install the auth on my yubikey. I never made it to my living room since it wasn’t so important to go, but definitely made me question my self why I should move from Authy app, to a yubikey. More secure? Probably....but I feel like you want a house without glass windows just for the ONE chance that burglars brake the windows and get in your house. Nobody is building a house without glass windows, right? Although the possibility is always there, that burglars can get in. I hope you understand my point! I will try to use my yubikeys since I bought them, but I don’t know how convenient they are to be honest.
@dhanushkavithanage232
@dhanushkavithanage232 3 года назад
Really good content, thanks. If the key is stolen how difficult would it be to retrieve stored data?Are the data encrypted on the key?
@daphbobo
@daphbobo 3 года назад
I like the grumpy man typing google authenticator code.
@daphbobo
@daphbobo 3 года назад
I use ubikey. I like it.
@azclaimjumper
@azclaimjumper 2 года назад
I now have my two 5NFC YubiKeys "Smart-Card Enabled" on both of my Macs meaning that the only way I can log onto either computer is to physically insert the Key into a USB port & enter the PIN. Passwords no longer work. Pairing my keys to each computer was easy peasy. Getting the "Smart-Card Enabled" on my computers required the same effort Generals in WWII had in planning the D Day invasion. Apple articles are incomplete & I never did find or talk with a Senior Tech Advisor that had ever even dealt with the codes required that need to be entered in Terminal. Either Passwords or the YubiKey can be used to log into a computer if "Smart-Card Enabled" isn't enabled which seems to me to defeat the purpose of YubiKeys. Yes, I've just subscribed & rang the notification bell. Warm Regards from Reno, Nevada.
@donovansobrero9553
@donovansobrero9553 3 года назад
been using a yubikey for years have a few of them. it's important to note if you set everything and then loss the key your going to have a problem. So its best to have two 1 you use and one you keep in a safe place with the same sites configured on it.
@matthewgrotke1442
@matthewgrotke1442 3 года назад
Thank you for the informative video. I was wondering if Google accepts Yubi Key for logging into Gmail, Google Account, etc.
@MrWarrenJH
@MrWarrenJH Год назад
Yes they do
@jeremyleonbarlow
@jeremyleonbarlow 3 года назад
I'm just under two minutes into the video, I'm hopeful that this provides an answer about what to do if you break one, because I have been known to break tiny things like a USB Key, so that has been my biggest fear about them. I mean do you have a backup key? Can you make new backups if you need to use the backup because the original broke?
@matthewsheeran
@matthewsheeran 2 года назад
Yes if I were to use them I would and you can have multiple keys. Just like backups go for 3 keys one of which is off site but in a secure place. One on you, a replacement hidden somewhere in the house and another secured off site. He is actually wrong or misunderstood when it comes to having multiple token generators: just like backups you have a sequence of secure backup keys.
@thomascruz210
@thomascruz210 2 года назад
Good
@3QuaNiMiTyy
@3QuaNiMiTyy Год назад
You can't make a backup of a Yubikey, each Yubikey will forever remain a separate key with its own identity. What you can do is have several Yubikeys affiliated with a single account such that losing one means you can use the other. Any lost key needs to be manually removed from an account/website.
@FirstLastOne
@FirstLastOne 3 года назад
I was intently listening to you describe why I should be using a Yubikey and looking at the artwork on the wall behind you. I know I am really tired and need more sleep but I thought I'd keep watching as long as I could and then it hit me as to why that artwork looked so familiar. When you terminate enough network cables in your life that you can do it in your sleep, things like the T-568B standard just becomes like a white wall or a white ceiling. It's there but you just don't see it and yet you known it there.
@samrichardson9827
@samrichardson9827 3 года назад
Pristine clear and relevent tube. Thanks so much for such a nice review of the Yubikey products !
@YuriShevchouk
@YuriShevchouk 3 года назад
When you talked with your yubikey engineer friend what did he say that made you use it.
@AlexsaurusRex
@AlexsaurusRex 3 года назад
Probably that it's faster than using authenticator apps on your smartphone. Also that he showed him how to use it since he was unaware of how they worked
@tedherman38
@tedherman38 3 года назад
Dangit Chris! I’ve been thinking about doing this for a while. 5C NFC is ordered.
@Inertia888
@Inertia888 3 года назад
I may be overly concerned about hackers, but personally I would not go with anything that is wireless when security is concerned. Wireless just provides one extra weak link in the chain. When using radio technology, i.e.: "NFC" I do suggest making yourself aware of the exact radius of that particular radio transmission.
@joshuanbray
@joshuanbray 3 года назад
@@Inertia888 Just the info I was looking for, thanks m8!
@johnzoidberg9764
@johnzoidberg9764 3 года назад
@@Inertia888 got credit/debit card?
@Inertia888
@Inertia888 3 года назад
@@johnzoidberg9764 yes, I do. and I change my numbers every few months just in case it has been compromised.
@justingreen8006
@justingreen8006 3 года назад
Thank you for explaining. I Just ordered a yubikey 5 nano yesterday. Unfortunately I only found your video today or I would have bought through your link.
@excitedsolutions1255
@excitedsolutions1255 3 года назад
Hi Chris, Great video. Do you know if you can use the UbiKey 5c NFC series as a NFC key for the Unifi Access Card/NFC Fob as well?
@bennettrichards6851
@bennettrichards6851 3 года назад
The only problem I have found with my YubiKey 5 NFC is that not all companies have changed their 2FA to use hardware Authorization... I wish YubiCo would update owners when they add new partners. Otherwise I love YubiKeys. They are about to come out with a Fingerprint YubiKey.
@triularity
@triularity 3 года назад
@16:46 - The collectable value on that special edition key dropped 99% the second you opened the original packaging. ;)
@alpham8754
@alpham8754 3 года назад
Thank you for that great product advertising. But I'm missing one topic completely: PGP transfered keys to the YubiKey: a) Usage in general b) What if you loose the YubiKey with the transferred private PGP key part? Just use the key backup that you hopefully did before transferring it? c) How do you revoke already published PGP keys from an lost YubiKey on the corresponding (public) PGP key servers? I'm currently struggling a bit with that YubiKey 5 NFC variant to use it with my PGP in order to sign or encrypt my mails on desktop client or on android client using the NFC interface...
@LinuxRacr
@LinuxRacr 3 года назад
As always, thank you for your in-depth videos! I have learned so much. One way to explain 2FA is that it is a subset of the term Strong Authentication. Strong auth works on the triad of, something you are, something you have, and something you know. Any two of those used together is strong auth, a.k.a. 2FA.
@josephrogersmd
@josephrogersmd 2 года назад
Thank you for your post. Can you explain to me the triad of “some thing you are“? I’m not sure what you mean by that. I understand the other two elements, something you having something you know.
@LinuxRacr
@LinuxRacr 2 года назад
@@josephrogersmd Something you are is basically biometrics. Fingerprint, iris scan, hand geometry scan, etc...
@SDWNJ
@SDWNJ 3 года назад
I can’t look at that painting in the background without thinking of pixie sticks.
@kd0dbw
@kd0dbw 3 года назад
It's the wiring order for a ethernet connector
@Agamerfr0zed
@Agamerfr0zed 3 года назад
Must have for Emails and Password managers. I just wished more websites would support security keys.
@TheCowboy4000
@TheCowboy4000 5 месяцев назад
Especially banks. Wish my bank and credit union would support it 😭
@andreasmahler3430
@andreasmahler3430 3 года назад
Thx Chris, Great Video, ... currently using it only for AAD auth, and I don't want to do without it anymore ...
@VikingCoffie
@VikingCoffie 3 года назад
Had one laying on my desk, after some testing some months ago. Did a second round after your video.... Now I am going to purchase a new keyboard and a second key.
@g-wizgeorge4454
@g-wizgeorge4454 3 года назад
You mentioned “losing” one of your Yubikeys. What’s the best practice for moving forward if you believe it to be truly lost or stolen? That would make a good video.
@Gersberms
@Gersberms 3 года назад
It depends on the account you lost. He briefly mentioned backup codes, I've seen that several times now that you get backup codes when you set up 2FA. Save those codes, and do not lose them. If you do, there may be no way back. I lost my Steam Authenticator, and had to contact support to get it straightened out. 2FA kind of worries me for that reason. Same problem with one time use texts, if you lose your number or your phone.
@ulbuilder
@ulbuilder 3 года назад
Get two yubikeys and lock one of them up in a safe place, many sites will let you register multiple MFA devices. So if you lose one you can log in with the other key, delete the lost one and register the replacement. On sites that do not allow that they will have some sort of backup code or method. Put that info in a safe place.
@AmandeepSingh-oe4te
@AmandeepSingh-oe4te 3 года назад
Simply buy ledger Nano s or Trezor T which only unlock after entering pin on the device. You only need to keep a 24 or 12 words backup if you lose your device, just buy another. They both offer Fido 2.
@Anaerin
@Anaerin 3 года назад
I'd love an answer to that too. How do you invalidate a Yubikey if it is lost or stolen, to stop it from being used maliciously, or is the only way to manually remove it from all your accounts? Is there no way to say "I no longer have this key, remove all the accounts from it"?
@ystebadvonschlegel3295
@ystebadvonschlegel3295 3 года назад
@@Anaerin Exactly - seems like you'd have to keep a list of everywhere it was registered and then go chasing them down manually. I know I won't do that (keep an up to date list)
@joselegarza148
@joselegarza148 3 года назад
Thank you, this took me over the top, I ordered Yubikeys (from your link, of course) for the family. One question remains. What happens with the lost backup Yubikey? Do you have to reset all the logins?
@bluekeybo
@bluekeybo 2 года назад
Add a password to it. So if someone steals it, they'd have to know both the yubikey password and the account password.
@jonathanshaw6784
@jonathanshaw6784 3 года назад
Regarding Tile, they work via bluetooth not GPS, so they will only give their location if they are near your phone (or near someone else's phone with the tile app). It works well for if you can't find your keys in your house or to check they're in a bag, much less useful for tracking a stolen bike.
@kstaxman2
@kstaxman2 2 года назад
Great info I'll be watching this video a few times to digest it all. Lots to consider.
@Nettechnologist
@Nettechnologist 3 года назад
I wish they had a screen for totp, with out having to plug in the device into a machine for those areas that we can’t install software nor plug usb into them
@jimmymifsud1
@jimmymifsud1 3 года назад
I’ve used the NFC on some secure industrial machines
@deusexaethera
@deusexaethera 3 года назад
RSA hardware keys exist.
@Nettechnologist
@Nettechnologist 3 года назад
@@deusexaethera Are you saying you can use RSA keys with Yubikey? I have extra RSA keys and didn't think this was possible
@dennisvanlith
@dennisvanlith 3 года назад
I absolutely love my YubiKey. The only downfall is the lack of support on many sites and web apps on the u2f protocol. I have tried many times to push these hardware keys on UniFi, Synology or others. But they rarely respond on the request, due to lack of the user base usage. The more people keep asking for these requests. The faster it will be taken into consideration.
@CCoburn3
@CCoburn3 Год назад
It’s a chicken or egg situation. No one wants to spend money on a piece of expensive junk that isn’t useful on more than a handful of sites that virtually no one uses. But no sites want to spend the resources to support Yubikey until more people buy them.
@ralphiem4207
@ralphiem4207 3 года назад
Hi, I just purchased the Yubikey 5 NFC. I have windows 10 home version and currently login with a pIn number. Is there an additional advantage to use Yubikey instead of logging in with the PIN for Windows 10? Will it be more secure if you do both? If yes, how do you implement that feature. Thanks.
@Stretch1931
@Stretch1931 2 года назад
I have some old Yubikey 4 as well as old Feitian and Titan keys when I turned on advanced protection on Google. But seeing your demonstration of the YubiKey authenticator, I've now purchased five of the YubiKey 5 FIPS keys and am excited to try them out. Something interestingly different is that the secrets are now (since YubiKey 5) are stored directly on the key instead of on your application. This will make it easier to use secrets from different devices without trusting a cloud service like Authy to keep the private keys on their servers.
@vze4p6c2
@vze4p6c2 3 года назад
Up next: Built in yubikey into cellphone for additional $300 for easy access
@TheBurzhui
@TheBurzhui 3 года назад
🤣👍
@bens1058
@bens1058 3 года назад
Google has already done this. The Titan chip is in some Google phones.
@magfal
@magfal 3 года назад
The basic hardware is there already, in sim cards.
@autohmae
@autohmae 3 года назад
Actually, many phones already have something like that build into it. So when your phone is unlocked, you can use it to log into systems. Both Android (since 7.x) and Apple. Apple and Windows laptops supposedly also support it. In Windows it's part of Windows Hello. In all cases I think they need to have a chip build in. Also Krypt Krypton might be an option.
@jpenn727
@jpenn727 3 года назад
I would love to be able to import my authy records into a yubi account.
@VPC
@VPC 3 года назад
Youd basically just go into your accounts and disable your authy 2 factor authentication, then set them up again but on the Yubi account
@kyleethekelt
@kyleethekelt 3 года назад
This is a most helpful video as I've been wondering how these work for some time. However, I am blind and use screen reading software and refreshable Braille. Would teh Ubico authenticator app be usable by me?
@ethanm9421
@ethanm9421 3 года назад
Thats crazy, i placed an order for one this morning!
@sethalton205
@sethalton205 3 года назад
It would be nice to see them integrate biometric authentication into it (an advantage of the smartphone) would also be nice if soft token MFAs got more into MFA push notifications for wearable devices. (Giving you the same one touch MFA experience as the ubikey).
@jhb5401
@jhb5401 3 года назад
YubiKey Bio is coming soon. Has a built in fingerprint reader.
@KyleJacksonplus
@KyleJacksonplus 3 года назад
Or you could just use Secret Double Octopus and get rid of your password all together.
@beardymcbeardface69
@beardymcbeardface69 3 года назад
I love using my Yubikeys and now they've brought out a model with a fingerprint reader, so... *TRIPLE* Factor for the win! Something you know, something you have, something you are!
@MoppelMat
@MoppelMat 3 года назад
I got one 5 NFC for 3/4 of a year now. Ordered it to do smartcard login to windows AD. To see that it can do soo much more is really intriguing! You said we can ask questions? Perfect! I just have a problem with the smartcard variant when try to use it against windows AD to a rdp server behind an RDP gateway. It just does not work, and I could not fix it. May you help me out with that case?
@quddus404
@quddus404 Год назад
If you kept it going till now you have all the respect that I can give
@evancjensen
@evancjensen 3 года назад
Google Authenticator now lets you log in and migrate devices, I believe. Edit: it requires the old device, but you can scan a QR code from the old device using the new device to migrate to the new device.
@CrosstalkSolutions
@CrosstalkSolutions 3 года назад
That's great news! Excellent update. Still...I would never go back because it can't do FIDO or other enhanced types of 2FA.
@evancjensen
@evancjensen 3 года назад
@@CrosstalkSolutions I couldn't agree more! Just wanted to point it out.
@djdrastic1
@djdrastic1 3 года назад
If you're lucky the old device hasn't suffered a hardware failure,fire,water damage,theft etc I had a charging port go on my Android phone and only realized by the end of the day that the thing wouldn't take a charge and had to literally make haste to get another old spare phone setup and migrate via QR . If I didn't notice it earlier I woulda been hosed pretty badly as I've got Google 2FA on pretty much everything.
@OlegObukhov
@OlegObukhov 3 года назад
All MFA apps allow you to migrate your accounts. All you need to know is backup/recovery codes that you were provided with the first time you signed in to the MFA app.
@evancjensen
@evancjensen 3 года назад
@@OlegObukhov up until this year, Google Authenticator did not. You'd have to redo every account...
@garethsnaim8174
@garethsnaim8174 3 года назад
This is a hard no for me, would be lost in a minute.
@donpeer4477
@donpeer4477 3 года назад
Did you not see the part where he lost his?
@Lyunpaw
@Lyunpaw 3 года назад
Best Yubikey video ever. I learned about this from a podcast but they just flew over the topic so fast I couldn't tell what to do with the damn thing; only that it was 2fa. Now I have a reason to buy a few to use for more security. I don't like using my phone for 2fa because I don't really trust the phone's os.
@ferulebezel
@ferulebezel 3 года назад
The problem I had with my Yubikey 4 was that google, facebook and twittter wouldn't allow you to enable it without giving them your phone number. The whole reason I got it was to avoid as many third parties getting involved and giving them something else by which to track me. Do you know if these issues have been fixed?
@matthewryan
@matthewryan 3 года назад
Hmm... Doesn't leaving the key plugged into your PC with the app running kind of defeat the object? Not unlike leaving your password on a post-it note under your keyboard really :-0
@warcorer
@warcorer 2 года назад
That’s why I prefer to use a password manager and have the yubikey work with the master password to access the manager.
@adamyork2333
@adamyork2333 2 года назад
Doesn't the yubikey (at least some models) still require biometric authentication before it works even if plugged in?
@word42069
@word42069 2 года назад
It would still need to be tapped by your fingers to activate… but yes, this has crossed my mind as well. For that I personally would steer clear of the “leave-in” ones… though i think the concerns are irrational for most security threats.
@ADeeSHUPA
@ADeeSHUPA Год назад
@@warcorer نَيس
@hyperfluff_folf
@hyperfluff_folf Год назад
In fact no, and thats why things like the trusted platform module and ssh keys exist, its just a second factor so if somebody wanted to hack your account they need your password too, or the other way around if they have your password they would need to hack the pc too to get the login done, but the yubikey requires button confirmation before login so thats fixed too
@ajbeau_au
@ajbeau_au 3 года назад
What about push notification to auth app? I can accept a prompt in about 2 seconds by accepting it on my watch. Just saying...
@VPC
@VPC 3 года назад
Convenience VS security
@seanknight9808
@seanknight9808 2 года назад
Hi Chris. Great video. Thanks! I will sure go to your link and buy a key. I do need a backup, as you said it is smart to have one. If someone buys a backup, does it have to be the same exact as the original? Or will a 5C NFC work well with a 5 NFC? Thanks!
@KevinSmall
@KevinSmall 3 года назад
Awesome video...one other question I have is how is the durability of these keys. I notice you have them on a Keychain with is usually thrown about casually.
@DonovanCYoung
@DonovanCYoung 3 года назад
Great video, but I'm not convinced it's better for personal use, you really can't beat something like 1password's cmd+/ (mac) or ctrl+/ (windows) key combo which fills your username, password, and when using OTP, the 2FA code when prompted. One and done. Also integrates into Safari and Chrome for iOS or Android. Truly a one-stop password app. Not to mention, it's stored in an encrypted vault, so it's shared between ALL your devices. Lastly, no limit on the number of sites you can use 2FA on. Yubikey seems good for large-scale 2FA implementations, but not for personal use... IMO
@liquicitizendirk2147
@liquicitizendirk2147 2 года назад
I think a middleground is perfect. Use yubikey for 1password and let 1password handle all other 2fa. I just googled and think it should work. You'd have the best of both worlds imo.
@paoloposo
@paoloposo Год назад
I think Chris got this wrong in his video. I'm not an expert on this, but I spent some time researching this because I wanted to know the technical details. If you're looking to replace authenticator apps that generate TOTP codes, a Yubikey or similar device can actually be used for an unlimited number of services. The 25 slot limit is for "Resident Keys" which are used for entirely password-less authentication schemes.
@jimk5145
@jimk5145 3 года назад
"I had a half-dozen yubikeys on my desk that I never used until Yubico contacted me to join their affiliate program, but the affiliate program had no influence on my endorsement of their product."
@KevinHoskinson647
@KevinHoskinson647 Год назад
😂😂😂😂
@GerryVeerman
@GerryVeerman Год назад
Looks like Yubidoobie is pumping loads of cash in influencing YT influencers. It’s Yubikey! wherever you go. Check out Rob Braxman for some real security tech.
@cydia2020
@cydia2020 Год назад
Still doesn't change the fact that hardware 2FA is much more safer and reliable compared to software/SMS alternatives when used correctly.
@AK-wm8lj
@AK-wm8lj 2 года назад
Can you advise me what I am doing wrong as my new yubiky is not registering when I insert in my iPhone. Also it’s it asks me to tap on the back of my phone but my yubi doesn’t have NFC which I realised is a downside but it should show up at least when I insert in my phone right? Thanks in advance
@robertortega8448
@robertortega8448 3 года назад
sooooo does it list your favs in the order they were added or alphabetically? Can I add favs in such a way that the order is to my preference?
@svampebob007
@svampebob007 3 года назад
Gotta love RU-vid recommendation: Up next: Breaking FIDO: Are Exploits in There? From Black Hat In all honesty I'm still slightly skeptical. I personally still only use passwords, and don't login on computers that I don't own/control. if I'm ever out and going and need to login to my bank or something like that I just use no-machine to connect back to my server at home and login thought that. I'm still not sure how trustworthy a for profit authentication company can be, when you have major player like google joining on the standards. I don't think there's a major security issue, I just don't think it's mature enough, on one side Google is fucked up, on the other Google (and other major players) have too much to lose if they start loosing reputation, so I don't think they would mess with authentication, but who's to say Yubikey can be trusted to not fuck up their protocol and chips being fundamentally flawed. The issue I have with all those passwords and double, triple checking of identity is that at the end they tend to try and make it easier to actually authenticate, and people end up using a 4 digit pin set to 0000, 1111, 1234 because some company made their old password insecure by forcing them to change it, make it too complicated, and have a trillion different login portals.
@BeateThomsen
@BeateThomsen 2 года назад
Thanks Chris for this informative video, do you know if the use of yubikeys are supported for the firefox browser?
@pe1pqx321
@pe1pqx321 3 года назад
Looks very interestign.. Just a question: let's say I need to access my NAS at home from a remote location (friends home for example). Does the Yubikey require software to be installed on the computer used to remotely access my NAS? (On the computer of my friend where I might be) Or is it 'plug & play'?
@ulbuilder
@ulbuilder 3 года назад
Whatever you are authenticating to must support some form of 2nd factor to work with a Yubikey. If your NAS supports a 2nd factor chances are it can work with a Yubikey. Yubikey has various models with differing capabilities but they have models that support some to all of the following types of MFA: HOTP, TOTP, U2F, FIDO, FIDO2 and PIV. Some, but not all, of those methods do require software on the computer using the key.
@MidianNiles
@MidianNiles 3 года назад
I apologize if I'm repeating a question, but I noticed that there are different security standards listed (NFC and FIPS). I was wondering if the FIPS security yubikeys work just like the NFC youbikeys? I'm asking because I'd like to know if the different security standards are cross-compatible; whether the FIPS standard is a more robust standard and if it's beneficial for standard web authentication. I guess I'm worried that if I get a yubikey with FIPS, I'll not have the versatility & ease of use like the NFC yubikeys.
@Onii-chans-neko
@Onii-chans-neko 3 года назад
so what program do i download to be able to use the yubikey codes on desktop, but not to sign into windows, a while back i installed the "yubikey for windows" program thinking it was just the version of the software for windows, but next time i turned on my computer it wanted a yubikey code... which i didn't have, had to restart/factory wipe the PC;
@EldonNeustaeter933
@EldonNeustaeter933 3 года назад
Excellent video ; I have an old one, time for an upgrade methinks. Also, I think some insight as to how this might work in an enterprise environment. Will it save sys admins time as well. I keep hearing about Google's Titan key effort but I wonder how a REAL business might function with a YubiKey implementation. Are there labour economics to warrant?
@Davino.F.Nascimento
@Davino.F.Nascimento 3 года назад
Thanks Chris. Extremely informative video.
@Hublium
@Hublium Год назад
Thank you for this very good introduction to the topic. My question is: What about open source alternatives to the Yubikey, are they any good?
@shetuamin
@shetuamin 3 года назад
Next year I buy this. Thanks for details review.
@pilkjaer
@pilkjaer 3 года назад
Good point about the company use case but there is a bit issue with that. Many companies, due to security reasons, disable USB ports on the devices so only keyboard/mouse will work and device charging. I wonder if 2FA device that is supposed to be plugged into USB will work as intended when this restriction is applied?
@davidecilano7271
@davidecilano7271 2 года назад
Hi Chris, Thanks for your Video!. I Have one question: In the case that I am having some shared desktop how does the Yubikey help me in invalidating the session once each operator disconnects his/her yubikey from the USB interface. The scenario is that sometimes the operators (that are using the same desktop) do not do logout. Is there any way to force login when a new Yubikey is connected and prompts for a new login?
@DontEatFibre
@DontEatFibre 3 года назад
What are your thoughts on OnlyKey? They can be quite instruction heavy to setup the first time, but they offer quite a bit of functionality.
@jfamtd2770
@jfamtd2770 3 года назад
what do you do for a device that has older Micro USB or Mini USB connectors and do not have NFC?
Далее
Debunking 5 MYTHS About Yubikey
15:36
Просмотров 189 тыс.
No one will play with him( #standoff #meme #grenade
00:12
Do This Now!  Yubikey + Google U2F Setup - EASY!
9:11
STOP Using Passwords!
17:19
Просмотров 29 тыс.
How Security Keys work (2FA explained!)
17:42
Просмотров 142 тыс.
How NVIDIA just beat every other tech company
9:20
Просмотров 1,2 млн
Protect 4.0 is Here - All New Features Explained
6:03
VLANs Made Easy: Learn This Today!
41:08
Просмотров 228 тыс.
12 Privacy & Security Tools I Use EVERY DAY
6:14
Просмотров 88 тыс.
Что не так с камерой 200мп?
0:56
Просмотров 58 тыс.
Prices & Poco M4 Pro 5G
1:00
Просмотров 264 тыс.
Красиво, но телефон жаль
0:32
Просмотров 1,4 млн