<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=4&amp;t=1661" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-12-18T08:40:00+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=4&amp;t=1661</id>
<entry>
<author><name><![CDATA[henrik]]></name></author>
<updated>2014-12-18T08:40:00+01:00</updated>
<published>2014-12-18T08:40:00+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6568#p6568</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6568#p6568"/>
<title type="html"><![CDATA[Re: Yubikey vs Google authenticator - Which one is the best?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6568#p6568"><![CDATA[
I just wanted to add a third advantage of Yubico Authenticator over Google Authenticator (and Authenticator Plus): It's <a href="https://github.com/Yubico/yubioath-android" class="postlink">open source</a>.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2968">henrik</a> — Thu Dec 18, 2014 8:40 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[DavidW]]></name></author>
<updated>2014-12-17T17:22:35+01:00</updated>
<published>2014-12-17T17:22:35+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6558#p6558</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6558#p6558"/>
<title type="html"><![CDATA[Re: Yubikey vs Google authenticator - Which one is the best?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6558#p6558"><![CDATA[
<div class="quotetitle">dvarapala wrote:</div><div class="quotecontent"><br /><div class="quotetitle">darco wrote:</div><div class="quotecontent">I'm also not sure if the keys in Google Authenticator will be transferred to a new phone when you upgrade.<br /></div><br /><br />Worst case, the secret used by the Google Authenticator app can be manually transferred to a new phone if necessary.</div><br /><br />You cannot read the secrets out of Google Authenticator unless the phone is rooted or you somehow gain direct access to the device's memory. If you change device and don't have copies of the secrets (e.g. hard copies of the QR codes), the easiest thing is to disable and re-enable two factor authentication on each of your accounts.<br /><br />If you want to transfer secrets between devices and hold them more securely on your device, try the <a href="https://play.google.com/store/apps/details?id=com.mufri.authenticatorplus" class="postlink">Authenticator Plus</a> app . The companion <a href="https://play.google.com/store/apps/details?id=com.mufri.authenticatorplus.legacyimport" class="postlink">Authenticator Plus Import</a> app that reads your credentials from Google Authenticator only works on rooted devices, and serves as proof of concept as to the security issues of storing credentials on a rooted device. I don't root my Android devices.<br /><br /><br />The best approach for me is to store all secrets that I use actively in a secure element (my Neo), with offline copies kept under multiple levels of encryption. I don't have my digital certificates, my OTP credentials or my PGP key and its subkeys stored on any device in a readily usable format.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3289">DavidW</a> — Wed Dec 17, 2014 5:22 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2014-12-17T13:16:21+01:00</updated>
<published>2014-12-17T13:16:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6554#p6554</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6554#p6554"/>
<title type="html"><![CDATA[Re: Yubikey vs Google authenticator - Which one is the best?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6554#p6554"><![CDATA[
My take on this question is the following:<br /><br />Google Authenticator is a piece of software that uses well know algorithms to generate on screen displayed codes (smartphones, tablets, pc).<br />In this scenario you have to trust your phone's hard-drive (tablet, pc, etc..) to store the secrets. These devices are often Internet connected.<br /><br />The Yubikey stores the secrets into the secure element. It is not an Internet connected device. The same well known algorithms are later on used to spit out the codes exactly as the Google Authenticator does onto the smartphone, tablets etc. However the secrets never leave the Yubike's secure element<br /><br />The Yubikey applet can be password protected.<br />The Google Authenticator doesn't (on iOS, however it could be easily added ),  it just prevents the average Joe to pick up the phone, start the App and steal couple of codes.<br /><br /><span style="color: #8000FF">The real question here is</span> 'do you trust storing secrets on the &quot;designed storage&quot; for your device app or you rather store them onto an offline device's secure element?'<br /><br />What do you think? I am happy to see great conversations about security coming up on this community!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Wed Dec 17, 2014 1:16 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[DavidW]]></name></author>
<updated>2014-12-17T01:42:39+01:00</updated>
<published>2014-12-17T01:42:39+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6538#p6538</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6538#p6538"/>
<title type="html"><![CDATA[Re: Yubikey vs Google authenticator - Which one is the best?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6538#p6538"><![CDATA[
<div class="quotetitle">dvarapala wrote:</div><div class="quotecontent"><br />My Galaxy Note 3 runs the Yubico Authenticator app but is unable to read either of my NEOs via NFC.<br /></div><br /><br />My Galaxy Note 3 works fine with my Neo, though I'm running a different country version to you and therefore different firmware (mine is BTU - United Kingdom unbranded). I will undoubtedly have different apps loaded to you. It's possible you have an app that is interfering with Yubico Authenticator and/or Yubiclip's use of NFC.<br /><br /><br />I'm therefore able to generate OTPs using the Authenticator app on my phone over NFC, or by using the Authenticator app on my laptop with the Neo in a USB slot.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3289">DavidW</a> — Wed Dec 17, 2014 1:42 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[DavidW]]></name></author>
<updated>2014-12-17T01:28:22+01:00</updated>
<published>2014-12-17T01:28:22+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6536#p6536</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6536#p6536"/>
<title type="html"><![CDATA[Re: Yubikey vs Google authenticator - Which one is the best?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6536#p6536"><![CDATA[
<div class="quotetitle">darco wrote:</div><div class="quotecontent"><br />Yubico Authenticator supports both event-based (HOTP) and time-based (TOTP) credentials, as does Google Authenticator, so this isn't really a differentiator as long as you have a good password on your YubiOATH app.<br /></div><br /><br />Adding to darco's answer, the majority of services online use TOTP, so you cannot generate OTPs in advance unless you have access to the secret and know the time you want the OTP for (typically a 30 second window, with the server making some allowance for entry time and clock skew).<br /><br />I have credentials for Google, Microsoft, Dropbox, Facebook, Tumblr and github on my Yubikey Neo. All are TOTP credentials.<br /><br /><br />The only event-based credentials I have are those I use with the Yubikey's 'touch button' capabilities: Yubico OTP (which I don't use much) and Symantec VIP (which I use with PayPal). I also have event based hardware OTP setups from two UK banks - HSBC uses a self-contained PIN protected token and Nationwide use a small device that works with the <a href="http://en.wikipedia.org/wiki/Chip_Authentication_Program" class="postlink">Chip Authentication Program</a> feature on their cards.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3289">DavidW</a> — Wed Dec 17, 2014 1:28 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2014-12-16T21:04:18+01:00</updated>
<published>2014-12-16T21:04:18+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6531#p6531</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6531#p6531"/>
<title type="html"><![CDATA[Re: Yubikey vs Google authenticator - Which one is the best?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6531#p6531"><![CDATA[
Yubico Authenticator supports both event-based (HOTP) and time-based (TOTP) credentials, as does Google Authenticator, so this isn't really a differentiator as long as you have a good password on your YubiOATH app.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Tue Dec 16, 2014 9:04 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[visibleninja]]></name></author>
<updated>2014-12-16T20:25:55+01:00</updated>
<published>2014-12-16T20:25:55+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6528#p6528</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6528#p6528"/>
<title type="html"><![CDATA[Re: Yubikey vs Google authenticator - Which one is the best?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6528#p6528"><![CDATA[
<div class="quotetitle">DavidW wrote:</div><div class="quotecontent"><br />With Google Authenticator, all your secrets are held on your phone, protected only by the device's encryption (if you enable it) and Android's isolation of application storage from other applications (if not rooted). Anyone getting hold of your unlocked phone can access your credentials.<br /><br />With the Yubikey, the secrets are held on a specialist security device and <strong>cannot be read out at all</strong>. If you have an Android device that works with your Yubikey Neo using NFC, it is really no more difficult to use the Yubikey system than Google Authenticator.<br /></div><br /><br />[My emphasis]<br /><br />One doesn't need to read the contents of a yubikey. The fact that the OTPs are not time-based makes it easier to &quot;hack&quot; than google-authenticator. All you've to do is get someone's yubikey, mail yourself some OTPs and then use them. Of-course once an OTP is used, all the past OTPs will be useless but still.<br /><br />I find Google-Authenticator in an encrypted password protected device much more secure than yubikey. I created this thread to be proved otherwise, as I might be starting to think that I made the wrong choice by going with Yubikey.<br /><br />Thank you all for posting on this thread btw.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3385">visibleninja</a> — Tue Dec 16, 2014 8:25 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2014-12-16T20:00:46+01:00</updated>
<published>2014-12-16T20:00:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6526#p6526</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6526#p6526"/>
<title type="html"><![CDATA[Re: Yubikey vs Google authenticator - Which one is the best?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6526#p6526"><![CDATA[
Ok, fair enough, I am assuming that the device is NFC compatible and works with the ykneo.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Tue Dec 16, 2014 8:00 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[dvarapala]]></name></author>
<updated>2014-12-16T19:59:12+01:00</updated>
<published>2014-12-16T19:59:12+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6525#p6525</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6525#p6525"/>
<title type="html"><![CDATA[Re: Yubikey vs Google authenticator - Which one is the best?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6525#p6525"><![CDATA[
<div class="quotetitle">darco wrote:</div><div class="quotecontent"><br />I'm also not sure if the keys in Google Authenticator will be transferred to a new phone when you upgrade.<br /></div><br /><br />Worst case, the secret used by the Google Authenticator app can be manually transferred to a new phone if necessary. <br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />The credentials on the yubikey will be available on any phone which can run the yubico authenticator app.<br /></div><br /><br />Not quite true. My Galaxy Note 3 runs the Yubico Authenticator app but is unable to read either of my NEOs via NFC.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3387">dvarapala</a> — Tue Dec 16, 2014 7:59 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2014-12-16T19:17:21+01:00</updated>
<published>2014-12-16T19:17:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6520#p6520</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6520#p6520"/>
<title type="html"><![CDATA[Re: Yubikey vs Google authenticator - Which one is the best?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6520#p6520"><![CDATA[
I'm also not sure if the keys in Google Authenticator will be transferred to a new phone when you upgrade. The credentials on the yubikey will be available on any phone which can run the yubico authenticator app.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Tue Dec 16, 2014 7:17 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[DavidW]]></name></author>
<updated>2014-12-16T19:13:13+01:00</updated>
<published>2014-12-16T19:13:13+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6519#p6519</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6519#p6519"/>
<title type="html"><![CDATA[Re: Yubikey vs Google authenticator - Which one is the best?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6519#p6519"><![CDATA[
With Google Authenticator, all your secrets are held on your phone, protected only by the device's encryption (if you enable it) and Android's isolation of application storage from other applications (if not rooted). Anyone getting hold of your unlocked phone can access your credentials.<br /><br />With the Yubikey, the secrets are held on a specialist security device and cannot be read out at all. If you have an Android device that works with your Yubikey Neo using NFC, it is really no more difficult to use the Yubikey system than Google Authenticator.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3289">DavidW</a> — Tue Dec 16, 2014 7:13 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[visibleninja]]></name></author>
<updated>2014-12-16T18:02:18+01:00</updated>
<published>2014-12-16T18:02:18+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6517#p6517</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6517#p6517"/>
<title type="html"><![CDATA[Yubikey vs Google authenticator - Which one is the best?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1661&amp;p=6517#p6517"><![CDATA[
Hey there!<br /><br />In your opinion, which is the best solution, Yubikey vs Google Authenticator?<br /><br /><br />I'm currently using Yubikey but I might start using google authenticator instead.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3385">visibleninja</a> — Tue Dec 16, 2014 6:02 pm</p><hr />
]]></content>
</entry>
</feed>