Google makes passkeys default across personal accounts

Lol this puts them out of business. Flogging a dead horse.
Anyone serious about security would keep using Yubikey.
The principles of security haven't changed and "something you have" is still one of the strongest levels of auth N.

In this case they are attempting to use a smart phone as "something you have" device.
But it has updatable software so still at a much lower security tier than a Yubikey which is a hardware smart card with no updateable firmware and is highly resistant to physical cloning (I'd say not possible but that is making a statement that I think can be overcome with enough time and money)
 
Anyone serious about security would keep using Yubikey.
The principles of security haven't changed and "something you have" is still one of the strongest levels of auth N.

In this case they are attempting to use a smart phone as "something you have" device.
But it has updatable software so still at a much lower security tier than a Yubikey which is a hardware smart card with no updateable firmware and is highly resistant to physical cloning (I'd say not possible but that is making a statement that I think can be overcome with enough time and money)
I always wonder with people that take security to a crazy level, why?
Unless that is you don’t know how to keep your passwords safe but otherwise no one can brute force your Google account because they only allow a few tries before you get locked out.
 
I always wonder with people that take security to a crazy level, why?
Unless that is you don’t know how to keep your passwords safe but otherwise no one can brute force your Google account because they only allow a few tries before you get locked out.
Why do you consider Yubikey crazy?
When you need to log into a new device, you type your password, then Google says you need to insert your security token, you do that and touch it, then remove it.
Then you are logged in.
I use a Yubikey for Google and payment because those are the things were I'm concerned about security (if someone got into those they could seriously ruin my life)
Everything else is password manager with randomly generated usernames and passwords (coincidentally if I need to sign into my password manager again I also do Auth N with Yubikey, but that is typically new device and such)
Yubikey has some other convenience things like SSH key storage/SSH key signing and so on but if you don't get the need for Yubikey I'm sure you don't use those.

https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F314f6099-8bd3-48cc-bd64-3f47a4e90be4_480x426.gif
 
Last edited:
Why do you consider Yubikey crazy?
When you need to log into a new device, you type your password, then Google says you need to insert your security token, you do that and touch it, then remove it.
Then you are logged in.
I use a Yubikey for Google and payment because those are the things were I'm concerned about security (if someone got into those they could seriously ruin my life)
Everything else is password manager with randomly generated usernames and passwords (coincidentally if I need to sign into my password manager again I also do Auth N with Yubikey, but that is typically new device and such)
Yubikey has some other connivence things like SSH key storage/SSH key signing and so on but if you don't get the need for Yubikey I'm sure you don't use those.

https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F314f6099-8bd3-48cc-bd64-3f47a4e90be4_480x426.gif
It’s definitely more secure but to my mind its overkill, are you afraid of potential key loggers or similar?
 
It’s definitely more secure but to my mind its overkill, are you afraid of potential key loggers or similar?
My phone getting stolen, cloned SIM card, "hacked", <insert something I haven't thought of here>
My phone goes everywhere with me.
I also connect my phone to just about any wifi (I travel a fair amount)
So overall I treat it as a tool and I'd like to assume zero trust with my phone.
My biggest concern is a remote exploit scenario since phones have a huge attack surface and updates flying back and forth all the time (with OSS which have had exploits embedded now so many times).

It is highly unlikely I'll get targeted, but for example LastPass was "recently" hacked and even though the passwords of everyone is zero trust (ie. encrypted on the client computer and they don't know the passwords).
They somehow got into a bunch of people's password vaults and stole tons of money (still unknown exactly how this was done, the best guess is weak master passwords)

So yeah the Yubikey is my, hardware is fixed, software is fixed, I have it in my hands device that cannot be cloned as a sanity check for my critical accounts.
 
Top
Sign up to the MyBroadband newsletter
X