<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=3&amp;t=101" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2008-06-16T00:00:00+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=3&amp;t=101</id>
<entry>
<author><name><![CDATA[Simon]]></name></author>
<updated>2008-06-16T00:00:00+01:00</updated>
<published>2008-06-16T00:00:00+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=101&amp;p=286#p286</id>
<link href="https://forum.yubico.com/viewtopic.php?t=101&amp;p=286#p286"/>
<title type="html"><![CDATA[Re: Clarification for online ID key generator and ID number]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=101&amp;p=286#p286"><![CDATA[
You are right that you can use any existing client id -- however, to verify the signature, you'll need the secret HMAC key that only the &quot;real&quot; client id holder would know.<br /><br />/Simon<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2">Simon</a> — Mon Jun 16, 2008 12:00 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[jwoltman]]></name></author>
<updated>2008-06-14T23:29:31+01:00</updated>
<published>2008-06-14T23:29:31+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=101&amp;p=276#p276</id>
<link href="https://forum.yubico.com/viewtopic.php?t=101&amp;p=276#p276"/>
<title type="html"><![CDATA[Re: Clarification for online ID key generator and ID number]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=101&amp;p=276#p276"><![CDATA[
The unchanging user ID number is only used as a convenient way to identify a Yubikey <strong>without</strong> having to know the private ID or the AES key.  You could, for example, use it to look up the AES key in a database, and then decode the rest of the one-time-password.  Then, using the database again, you could check the OTP's private ID with the one you stored in the database.<br /><br />If someone were to spoof your public user ID, they still wouldn't know the correct private ID or AES key.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=125">jwoltman</a> — Sat Jun 14, 2008 11:29 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[julian46]]></name></author>
<updated>2008-06-14T14:02:21+01:00</updated>
<published>2008-06-14T14:02:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=101&amp;p=272#p272</id>
<link href="https://forum.yubico.com/viewtopic.php?t=101&amp;p=272#p272"/>
<title type="html"><![CDATA[Clarification for online ID key generator and ID number]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=101&amp;p=272#p272"><![CDATA[
Has anyone else noticed that when testing the webclients (so far for md the PHP and C ones) - that you can supply any user ID number - not just the one genned for your key.<br /><br />For instance when testing the C client - I can run the supplied compiled C program with the following:<br /><br />YubicoClient 125 (press Yubikey here) - and it will reply with a pass.<br />----------------------------<br />* OTP verified OK<br />* Last response: t=2008-06-15T20:14:22Z0438<br />status=OK<br />----------------------------<br /><br />You can do this with any number - as long as the web api has genned it online.<br /><br />Am I mistaken - or should it only work for my individual key?<br />(IE - I have to use 139 - because my key was genned with the &quot;online API key generator&quot; and it displayed 139)<br /><br />thanks<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=130">julian46</a> — Sat Jun 14, 2008 2:02 pm</p><hr />
]]></content>
</entry>
</feed>