<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=1251" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2013-12-08T08:09:37+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=1251</id>
<entry>
<author><name><![CDATA[yomo768]]></name></author>
<updated>2013-12-08T08:09:37+01:00</updated>
<published>2013-12-08T08:09:37+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4708#p4708</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4708#p4708"/>
<title type="html"><![CDATA[Re: [QUESTION] Procedure to access Win 8 when Yubikey is los]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4708#p4708"><![CDATA[
<div class="quotetitle">Tom wrote:</div><div class="quotecontent"><br />Password can easily be stolen, cracked or snooped from a remote attacker around the world, while the Yubikey it is with you and can potentially only be &quot;stolen&quot; by the very few people around you.<br /><br />Moreover, the Yubikey secrets cannot remotely stolen.<br /></div><br /><br />So there are 2 types of attacks that need to be considered, local and remote.<br /><br /><div class="quotetitle">Tom wrote:</div><div class="quotecontent"><br />A 100 characters password will not give you anything more then a 20 characters password (practically not theoretically). They are both to long to be guessed (but steal be be stolen/lost/cracked)<br /></div><br /><br />In terms of Windows logon I imagine one would need to have RDP enabled for a remote attack to happen against one's Windows account. As far as getting the password, although a long password would protect against a stolen SAM file with the hashed passwords, it would not protect against a keystroke logger which is what you imply when you wrote that it could be stolen regardless of length, right?<br /><br /><div class="quotetitle">Tom wrote:</div><div class="quotecontent"><br />You can always enable the &quot;safe mode&quot; in the logon tool. This will allow you to reboot your machine in safe mode and login without the Yubikey.<br /></div><br />So enabling 'safe mode' in the logon tool, (which is the default), would not protect against local attacks, but would still protect against remote attacks since a remote attacker would not be able to physically reboot the machine in safe mode, right?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2727">yomo768</a> — Sun Dec 08, 2013 8:09 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom]]></name></author>
<updated>2013-12-07T12:55:26+01:00</updated>
<published>2013-12-07T12:55:26+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4701#p4701</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4701#p4701"/>
<title type="html"><![CDATA[Re: [QUESTION] Procedure to access Win 8 when Yubikey is los]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4701#p4701"><![CDATA[
No.<br /><br />The strength resides in the fact that you have something you &quot;know&quot; the password and something you have &quot;the Yubikey&quot;<br /><br />Password can easily be stolen, cracked or snooped from a remote attacker around the world, while the Yubikey it is with you and can potentially only be &quot;stolen&quot; by the very few people around you.<br /><br />Moreover, the Yubikey secrets cannot remotely stolen.<br /><br />A 100 characters password will not give you anything more then a 20 characters password (practically not theoretically). They are both to long to be guessed (but steal be be stolen/lost/cracked)<br /><br />You can always enable the &quot;safe mode&quot; in the logon tool. This will allow you to reboot your machine in safe mode and login without the Yubikey.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2195">Tom</a> — Sat Dec 07, 2013 12:55 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[yomo768]]></name></author>
<updated>2013-12-06T17:57:16+01:00</updated>
<published>2013-12-06T17:57:16+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4698#p4698</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4698#p4698"/>
<title type="html"><![CDATA[Re: [QUESTION] Procedure to access Win 8 when Yubikey is los]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4698#p4698"><![CDATA[
<div class="quotetitle">Tom wrote:</div><div class="quotecontent"><br />You can create a backup of your Yubikey on a second Yubikey.<br /></div><br />I only have 1 Yubikey so that's not possible.<br /><br /><div class="quotetitle">Tom wrote:</div><div class="quotecontent"><br />If you have 2 &quot;admin&quot; account one with Two Factor Authentication and one without, you are basically voiding any benefit.<br /></div><br />However, my day-to-day account contains a shorter password, which, combined with the Yubikey makes it more secure. My recovery admin account password would contain for example, 100 characters so that should be a good compromise, right?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2727">yomo768</a> — Fri Dec 06, 2013 5:57 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom]]></name></author>
<updated>2013-12-06T08:34:02+01:00</updated>
<published>2013-12-06T08:34:02+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4697#p4697</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4697#p4697"/>
<title type="html"><![CDATA[Re: [QUESTION] Procedure to access Win 8 when Yubikey is los]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4697#p4697"><![CDATA[
You can create a backup of your Yubikey on a second Yubikey.<br /><br />If you have 2 &quot;admin&quot; account one with Two Factor Authentication and one without, you are basically voiding any benefit.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2195">Tom</a> — Fri Dec 06, 2013 8:34 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[yomo768]]></name></author>
<updated>2013-12-06T06:13:55+01:00</updated>
<published>2013-12-06T06:13:55+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4696#p4696</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4696#p4696"/>
<title type="html"><![CDATA[[QUESTION] Procedure to access Win 8 when Yubikey is lost]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1251&amp;p=4696#p4696"><![CDATA[
I have Windows 8 challenge response integrated with the Yubikey and would like to know what to do if the Yubikey is lost in terms of accessing Windows 8. Should a separate administrator account be created without the Yubikey integration? Or is there a better way without creating an additional account?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2727">yomo768</a> — Fri Dec 06, 2013 6:13 am</p><hr />
]]></content>
</entry>
</feed>