<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=4&amp;t=547" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2011-09-08T12:09:57+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=4&amp;t=547</id>
<entry>
<author><name><![CDATA[matthewbloch]]></name></author>
<updated>2011-09-08T12:09:57+01:00</updated>
<published>2011-09-08T12:09:57+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=547&amp;p=2797#p2797</id>
<link href="https://forum.yubico.com/viewtopic.php?t=547&amp;p=2797#p2797"/>
<title type="html"><![CDATA[Re: When will yubikey become a brick? locking myself out?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=547&amp;p=2797#p2797"><![CDATA[
Can I resurrect this thread to ask what happens to the timer after 24.47 days? Does it wrap, or get stuck? <!-- m --><a class="postlink" href="http://wiki.yubico.com/wiki/index.php/Yubikey">http://wiki.yubico.com/wiki/index.php/Yubikey</a><!-- m --> says &quot;the session is terminated and no more OTPs can be generated&quot; but one of our customers kept getting OTPs after 25 days, just not that our server would validate. I've not got a log of the tokens generated, so can you fill me in on what to expect the timer value to show?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1506">matthewbloch</a> — Thu Sep 08, 2011 12:09 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Jakob]]></name></author>
<updated>2010-07-03T23:38:11+01:00</updated>
<published>2010-07-03T23:38:11+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=547&amp;p=2265#p2265</id>
<link href="https://forum.yubico.com/viewtopic.php?t=547&amp;p=2265#p2265"/>
<title type="html"><![CDATA[Re: When will yubikey become a brick? locking myself out?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=547&amp;p=2265#p2265"><![CDATA[
<div class="quotetitle">tdlk wrote:</div><div class="quotecontent"><br />I'm using my yubikey for openid and keygenius =) love it.<br /></div><br />Always nice to hear <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /><br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />Now I have some questions:<br /><br />1) How many power-ups do I have? (non-volatile counter)<br /></div><br />Hard to say. Assuming Yubico OTP mode, the Yubikey counts up the first time an OTP is generated after power up. Then the session counter counts up<br />The use counter is limted to 15 bits, which today seems a bit stupid, trying to stuff bits as tight as possible. But, assuming even five power-ups per day, 365 days per year it will still take 32768 / 5 / 365 = 18 years for the counter to get stuck. I strongly doubt that it will ever happen to any [normal] user... <br /><br />In OATH-HOTP mode, the counter is 16-bits, thereby expanding to double that number. OTOH, in HOTP mode, the non-volatile counter counts up every time the Yubikey is used.<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />2) Is it reset when a new AES/OTP config is programmed?<br /></div><br />Yes. If the counter eventually would hit the wall, the key can always be re-configured. Then the counter is back at zero again.<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />3) Do the session/global counters wrap-around eventually?<br />4) How many OTPs can I generate per power-up (e.g. 48h coding session =) )?<br /></div><br />In Yubico OTP mode, the counter gets stuck at 32767. In HOTP mode, it wraps from 65535 -&gt; 0. <br />The session counter is 8 bits wide, giving 256 counts per power up cycle. If this counter wraps, the use counter is incremented, thereby avoiding a clash.<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />5) Chicken &amp; Egg problems: is it possible to use yubikey OTP for pam logins into Gnome Desktop? Encrypted home partition? How to solve this if pam is used to unlock gnome-keyring, gnome-keyring stores WiFi passwords, and WiFi is needed to connect to yubico server to authenticate pam? Also what about using pam to access gpg keys and encrypted home? any suggestions. Or shall I use static passwords for this?<br /></div><br />Seems like a static password would be best here. You can always use the second configuration for that.<br /><br /><br />Best regards,<br />JakobE<br />Hardware- and firmware guy @ Yubico<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=83">Jakob</a> — Sat Jul 03, 2010 11:38 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tdlk]]></name></author>
<updated>2010-06-25T13:01:21+01:00</updated>
<published>2010-06-25T13:01:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=547&amp;p=2263#p2263</id>
<link href="https://forum.yubico.com/viewtopic.php?t=547&amp;p=2263#p2263"/>
<title type="html"><![CDATA[When will yubikey become a brick? locking myself out?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=547&amp;p=2263#p2263"><![CDATA[
I'm using my yubikey for openid and keygenius =) love it.<br /><br />Now I have some questions:<br /><br />1) How many power-ups do I have? (non-volatile counter)<br /><br />2) Is it reset when a new AES/OTP config is programmed?<br /><br />3) Do the session/global counters wrap-around eventually?<br /><br />4) How many OTPs can I generate per power-up (e.g. 48h coding session =) )?<br /><br />5) Chicken &amp; Egg problems: is it possible to use yubikey OTP for pam logins into Gnome Desktop? Encrypted home partition? How to solve this if pam is used to unlock gnome-keyring, gnome-keyring stores WiFi passwords, and WiFi is needed to connect to yubico server to authenticate pam? Also what about using pam to access gpg keys and encrypted home? any suggestions. Or shall I use static passwords for this?<br /><br />Thanks =)<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1240">tdlk</a> — Fri Jun 25, 2010 1:01 pm</p><hr />
]]></content>
</entry>
</feed>