<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=4&amp;t=2395" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-03-27T14:22:55+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=4&amp;t=2395</id>
<entry>
<author><name><![CDATA[Shadoninja]]></name></author>
<updated>2017-03-27T14:22:55+01:00</updated>
<published>2017-03-27T14:22:55+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2395&amp;p=9503#p9503</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=9503#p9503"/>
<title type="html"><![CDATA[Re: Gmail pretends to let you use Yubikey... why...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=9503#p9503"><![CDATA[
<div class="quotetitle">SporkWitch wrote:</div><div class="quotecontent"><br />It really doesn't, unless you play a 6-degrees-of-separation game with synonyms.  &quot;Completely mitigates&quot; is a nonsensical statement; mitigation, by definition, is incomplete.  If it were complete, it wouldn't have been mitigated, it would have been fixed or some other term that implies finality and completeness.<br /><br />Per Oxford:<br />1) Make (something bad) less severe, serious, or painful<br />1.1) Lessen the gravity of (an offence or mistake)<br /><br />No other definitions are recognized.  Most others (dictionaries) match or are nearly identical to the above.  I cannot even find anything that gets close to your redefinition as &quot;weakens&quot;.<br /></div><br /><br />Are you actually arguing about this? I don't think anyone would read my original post and get confused. Not sure what you are trying to accomplish here besides maintaining a big head. Having an account accessible through a Yubikey AND a phone is less secure than having an account accessible through a Yubikey alone. You can spew off all the auth technologies and ways things fail and whatnot, but you can't argue against the security differences between one key to a safe and two keys to a safe.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4438">Shadoninja</a> — Mon Mar 27, 2017 2:22 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[SporkWitch]]></name></author>
<updated>2016-11-20T02:02:58+01:00</updated>
<published>2016-11-20T02:02:58+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2395&amp;p=9161#p9161</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=9161#p9161"/>
<title type="html"><![CDATA[Re: Gmail pretends to let you use Yubikey... why...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=9161#p9161"><![CDATA[
It really doesn't, unless you play a 6-degrees-of-separation game with synonyms.  &quot;Completely mitigates&quot; is a nonsensical statement; mitigation, by definition, is incomplete.  If it were complete, it wouldn't have been mitigated, it would have been fixed or some other term that implies finality and completeness.<br /><br />Per Oxford:<br />1) Make (something bad) less severe, serious, or painful<br />1.1) Lessen the gravity of (an offence or mistake)<br /><br />No other definitions are recognized.  Most others (dictionaries) match or are nearly identical to the above.  I cannot even find anything that gets close to your redefinition as &quot;weakens&quot;.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4454">SporkWitch</a> — Sun Nov 20, 2016 2:02 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bannon]]></name></author>
<updated>2016-11-01T02:14:38+01:00</updated>
<published>2016-11-01T02:14:38+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2395&amp;p=9134#p9134</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=9134#p9134"/>
<title type="html"><![CDATA[Re: Gmail pretends to let you use Yubikey... why...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=9134#p9134"><![CDATA[
Completely mitigates the security, may be interpreted as ultimately weakens the security. Mitigate means to make less severe, but it also means weakens.<br /><br /><br /><div class="quotetitle">SporkWitch wrote:</div><div class="quotecontent"><br /><div class="quotetitle">Shadoninja wrote:</div><div class="quotecontent">I use my Yubikey with my LastPass and I love it. I use my Yubikey with GMail and.... well it is pointless. Google forces you to have your phone set up as a backup 2-factor auth. I have two Yubikeys and backup codes setup on my GMail and they still force the phone 2-factor to be setup. If you try to login and click the &quot;I don't have my security key&quot; button, you can continue using your phone as if the Yubikey was never part of the equation. This completely mitigates the security benefits of Yubikey. What makes this even worse is if you can get to my email account, you can reset my LastPass account too. So my phone is still the point of failure in my security setup at the moment even though I have upgraded to a dongle. <br /><br />Has anyone else noticed this?<br /></div><br /><ol style="list-style-type: decimal"><li>You don't seem to know what &quot;completely&quot; or &quot;mitigates&quot; mean.  Not only do the words not make sense when combined, but they don't apply here.  You seem to think that having the phone as a backup invalidates the gains of the yubikey when it does not.</li><li>Your phone should already be secured reasonably, and as such, the OTP if this method is used is reasonably secure.  If you're using U2F, rather than auth, then your phone is actually <em>more</em> secure.</li><li>If you're using auth and just storing the tokens on the yubikey, then yes, the phone messages result in a very marginal reduction in security (it's still better than storing the keys on the phone, since there's no secret to be surreptitiously stolen, but it's not as good as yubikey + phone, since it only requires getting into the phone and your text message application; in my case that's yet another layer, since I use Signal).</li></ol><br />Now, is it perfect?  No.  But it is definitely a significant improvement over the alternatives, both in convenience and security.  As far as the phone being SPOF, that was the case either way.  If they didn't have the phone number backup they'd still have access to the mail anyway as you've probably got it programmed on the phone.  There's not really any getting around it, other than to look into using the yubikey itself to unlock the phone (this is doable, but requires root and a fair bit of modification; you also risk locking yourself out quite thoroughly).</div><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4526">bannon</a> — Tue Nov 01, 2016 2:14 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[SporkWitch]]></name></author>
<updated>2016-09-02T05:39:37+01:00</updated>
<published>2016-09-02T05:39:37+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8943#p8943</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8943#p8943"/>
<title type="html"><![CDATA[Re: Gmail pretends to let you use Yubikey... why...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8943#p8943"><![CDATA[
<div class="quotetitle">mouse008 wrote:</div><div class="quotecontent"><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent">so far as I know, so yes, you could install the usual Google services, but this would largely defeat the point (they're also not guaranteed to work, as Copperhead does tighten somethings down and isn't really concerned about making sure the stock google stuff is happy)<br /></div><br />Well, since many people (myself included) want smartphones because of the applications they can run on it, rather than the pleasure of owning a powerful pocket-size computer with a secure OS - while I don't intend to download and run the entire Play Store warehouse, there are apps that I need to run (no, not games <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" />. So if Copperhead tightens things up so some apps might not run - I probably can live with that (since the apps I'm concerned for aren't &quot;tricky&quot;), but if only some apps would run while the majority won't - then I'll probably skip...</div><br />It uses the F-droid marketplace by default, but we're really getting into the realm of &quot;google questions&quot; at this point; these are things you could look up in less time than it takes me to notice and reply lol<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4454">SporkWitch</a> — Fri Sep 02, 2016 5:39 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mouse008]]></name></author>
<updated>2016-09-02T05:22:20+01:00</updated>
<published>2016-09-02T05:22:20+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8942#p8942</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8942#p8942"/>
<title type="html"><![CDATA[Re: Gmail pretends to let you use Yubikey... why...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8942#p8942"><![CDATA[
<div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />so far as I know, so yes, you could install the usual Google services, but this would largely defeat the point (they're also not guaranteed to work, as Copperhead does tighten somethings down and isn't really concerned about making sure the stock google stuff is happy)<br /></div><br />Well, since many people (myself included) want smartphones because of the applications they can run on it, rather than the pleasure of owning a powerful pocket-size computer with a secure OS - while I don't intend to download and run the entire Play Store warehouse, there are apps that I need to run (no, not games <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" />. So if Copperhead tightens things up so some apps might not run - I probably can live with that (since the apps I'm concerned for aren't &quot;tricky&quot;), but if only some apps would run while the majority won't - then I'll probably skip...<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4029">mouse008</a> — Fri Sep 02, 2016 5:22 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[SporkWitch]]></name></author>
<updated>2016-09-02T04:39:59+01:00</updated>
<published>2016-09-02T04:39:59+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8940#p8940</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8940#p8940"/>
<title type="html"><![CDATA[Re: Gmail pretends to let you use Yubikey... why...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8940#p8940"><![CDATA[
Copperhead is still binary compatible with Android, so far as I know, so yes, you could install the usual Google services, but this would largely defeat the point (they're also not guaranteed to work, as Copperhead does tighten somethings down and isn't really concerned about making sure the stock google stuff is happy).  I'm planning on trying it out as soon as I can afford a replacement phone (I have a Nexus 6, but I make a point of not doing custom ROMs unless I can afford to replace the device in case the worst happens).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4454">SporkWitch</a> — Fri Sep 02, 2016 4:39 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mouse008]]></name></author>
<updated>2016-09-02T03:43:29+01:00</updated>
<published>2016-09-02T03:43:29+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8937#p8937</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8937#p8937"/>
<title type="html"><![CDATA[Re: Gmail pretends to let you use Yubikey... why...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8937#p8937"><![CDATA[
<div class="quotetitle">SporkWitch wrote:</div><div class="quotecontent"><br />It's all relative.  If you treat your phone like a computer, it's not really at much more risk than your computer is, at least as far as what you're talking about.  You can make a phone reasonably secure...<br /></div><br />True, it's all relative. However there is a reason that security-conscious organizations move towards hardware tokens for keeping/using cryptographic keys (remote access, S/MIME) <span style="text-decoration: underline">and</span> for computer login.<br /><br />But one important difference is - both your computer and your phone are likely to have malware that can harvest your keystrokes and browse through your files. A smart card is much less likely to be penetrated in that manner, so the keys it houses can be reasonably assumed to be secure (unlike anything that is stored on the computer, or on the phone).<br /><br /><div class="quotetitle">SporkWitch wrote:</div><div class="quotecontent"><br />...and if you're not satisfied with stock, there's things like <a href="https://copperhead.co/android/" class="postlink">Copperhead OS</a>.<br /></div><br />Ha! I did not follow - thanks for mentioning it. Do you happen to know if it would run standard Android applications from Google Play Store? Or would everything have to be recompiled from the source?<br /><br /><div class="quotetitle">SporkWitch wrote:</div><div class="quotecontent"><br />The reason I say that the phone is _more_ secure than U2F is simple: U2F merely requires physical possession of the token (this is why I still have a passphrase on my laptop _in addition_ to U2F from the yubikey, and not just U2F; think of U2F like the DRM dongles that were popular with expensive software in the 80's and early 90's).<br /></div><br />I see your point. In the majority of my use cases the token is employed as a PIV card, so in addition to the mere physical possession you need to know the PIN. Returning to U2F though - consider the <strong>2F</strong> part of it. You don't even get to touching the button on the token until you satisfied the remote end that you know the correct password. So the adversary needs <span style="text-decoration: underline">both</span> your password, and your physical token. Not impossible, but far less likely - especially for a remote attacker.<br /><br /><div class="quotetitle">SporkWitch wrote:</div><div class="quotecontent"><br />A text message, on the other hand, can be behind multiple passphrases (your phone's unlock code, and in my case, signal's separate passphrase; although the code was unencrypted in transit, the local copy is encrypted).  Similarly, PGP and PIV both require the PIN to use.<br /></div><br />Once the malware (usually through a compromised application or one of many compromised ad-libs) gets on the phone (or on the computer), the unlock code does not matter any more. Somewhat better with Signal (presumably acting as a protected container within the phone space), but still - software is roughly equal to paper walls, practical for exploitation by <span style="text-decoration: underline">remote</span> attackers (something that is less feasible with U2F). But I see your point.<br /><br /><div class="quotetitle">SporkWitch wrote:</div><div class="quotecontent"><br />As far as using the yubikey to unlock the phone, here's one example (not particularly difficult, but not without its trade-offs): <!-- m --><a class="postlink" href="https://nelenkov.blogspot.com/2014/03/unlocking-android-using-otp.html">https://nelenkov.blogspot.com/2014/03/u ... g-otp.html</a><!-- m --><br /><br /><strong>EDIT: The Nexus 6 supports NFC unlock out of the box via the Smart Lock feature.  Only hitch is to make sure you have the YubiClip application installed so that it catches the URI the tag opens (if you don't, it tries to open the OTP URI in your default browser; if you do have it installed it loads the OTP into the clipboard, which is much less intrusive, and more importantly, has less chance of leaking (if you modify the NDEF to have NFC give a static password instead of Yubico OTP, it opening the browser would leak the static password to Yubico).</strong><br /></div><br />That is very nice to know, thank you!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4029">mouse008</a> — Fri Sep 02, 2016 3:43 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[SporkWitch]]></name></author>
<updated>2016-08-30T16:35:17+01:00</updated>
<published>2016-08-30T16:35:17+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8926#p8926</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8926#p8926"/>
<title type="html"><![CDATA[Re: Gmail pretends to let you use Yubikey... why...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8926#p8926"><![CDATA[
<div class="quotetitle">mouse008 wrote:</div><div class="quotecontent"><br />It's weird to hear the words &quot;phone&quot; and &quot;reasonably secure&quot; is the same statement. One advantage of tokens like YubiKey is that they aren't likely to carry malware, unlike most smartphones (regardless of whether you do install games on them or not <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /> ).<br /><br />In my universe people don't say that PK-based U2F is <em>less</em> secure than a phone-generated OTP. <br /><br />Having a phone as a backup is a valid option, but it definitely is of a lower security level than a PK-based YubiKey authentication (PIV, OpenPGP, U2F). <em>I have no opinion on OTP.</em><br /><br />Have to concede that some form of a backup is necessary because one can lose or damage his token (however unlikely that might be for some people). Pre-generated access codes work, and a smartphone as a backup works too. <br /><br />P.S. Securing the phone itself with a YubiKey may work for Android (I suspect a good amount of contortions required to accomplish it), and practically impossible for Apple (iPhone, iPod, iPad) devices. <em>If you know otherwise - please do enlighten me.</em>  And it does not defend against the phone being compromised by malware.<br /></div><br />It's all relative.  If you treat your phone like a computer, it's not really at much more risk than your computer is, at least as far as what you're talking about.  You can make a phone reasonably secure (and if you're not satisfied with stock, there's things like <a href="https://copperhead.co/android/" class="postlink">Copperhead OS</a>.<br /><br />The reason I say that the phone is _more_ secure than U2F is simple: U2F merely requires physical possession of the token (this is why I still have a passphrase on my laptop _in addition_ to U2F from the yubikey, and not just U2F; think of U2F like the DRM dongles that were popular with expensive software in the 80's and early 90's).  A text message, on the other hand, can be behind multiple passphrases (your phone's unlock code, and in my case, signal's separate passphrase; although the code was unencrypted in transit, the local copy is encrypted).  Similarly, PGP and PIV both require the PIN to use.<br /><br />As far as using the yubikey to unlock the phone, here's one example (not particularly difficult, but not without its trade-offs): <!-- m --><a class="postlink" href="https://nelenkov.blogspot.com/2014/03/unlocking-android-using-otp.html">https://nelenkov.blogspot.com/2014/03/u ... g-otp.html</a><!-- m --><br /><br /><strong>EDIT: The Nexus 6 supports NFC unlock out of the box via the Smart Lock feature.  Only hitch is to make sure you have the YubiClip application installed so that it catches the URI the tag opens (if you don't, it tries to open the OTP URI in your default browser; if you do have it installed it loads the OTP into the clipboard, which is much less intrusive, and more importantly, has less chance of leaking (if you modify the NDEF to have NFC give a static password instead of Yubico OTP, it opening the browser would leak the static password to Yubico).</strong><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4454">SporkWitch</a> — Tue Aug 30, 2016 4:35 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mouse008]]></name></author>
<updated>2016-08-29T02:58:22+01:00</updated>
<published>2016-08-29T02:58:22+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8920#p8920</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8920#p8920"/>
<title type="html"><![CDATA[Re: Gmail pretends to let you use Yubikey... why...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8920#p8920"><![CDATA[
It's weird to hear the words &quot;phone&quot; and &quot;reasonably secure&quot; is the same statement. One advantage of tokens like YubiKey is that they aren't likely to carry malware, unlike most smartphones (regardless of whether you do install games on them or not <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /> ).<br /><br />In my universe people don't say that PK-based U2F is <em>less</em> secure than a phone-generated OTP. <br /><br />Having a phone as a backup is a valid option, but it definitely is of a lower security level than a PK-based YubiKey authentication (PIV, OpenPGP, U2F). <em>I have no opinion on OTP.</em><br /><br />Have to concede that some form of a backup is necessary because one can lose or damage his token (however unlikely that might be for some people). Pre-generated access codes work, and a smartphone as a backup works too. <br /><br />P.S. Securing the phone itself with a YubiKey may work for Android (I suspect a good amount of contortions required to accomplish it), and practically impossible for Apple (iPhone, iPod, iPad) devices. <em>If you know otherwise - please do enlighten me.</em>  And it does not defend against the phone being compromised by malware.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4029">mouse008</a> — Mon Aug 29, 2016 2:58 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[SporkWitch]]></name></author>
<updated>2016-08-27T20:41:08+01:00</updated>
<published>2016-08-27T20:41:08+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8913#p8913</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8913#p8913"/>
<title type="html"><![CDATA[Re: Gmail pretends to let you use Yubikey... why...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8913#p8913"><![CDATA[
<div class="quotetitle">Shadoninja wrote:</div><div class="quotecontent"><br />I use my Yubikey with my LastPass and I love it. I use my Yubikey with GMail and.... well it is pointless. Google forces you to have your phone set up as a backup 2-factor auth. I have two Yubikeys and backup codes setup on my GMail and they still force the phone 2-factor to be setup. If you try to login and click the &quot;I don't have my security key&quot; button, you can continue using your phone as if the Yubikey was never part of the equation. This completely mitigates the security benefits of Yubikey. What makes this even worse is if you can get to my email account, you can reset my LastPass account too. So my phone is still the point of failure in my security setup at the moment even though I have upgraded to a dongle. <br /><br />Has anyone else noticed this?<br /></div><br /><ol style="list-style-type: decimal"><li>You don't seem to know what &quot;completely&quot; or &quot;mitigates&quot; mean.  Not only do the words not make sense when combined, but they don't apply here.  You seem to think that having the phone as a backup invalidates the gains of the yubikey when it does not.</li><li>Your phone should already be secured reasonably, and as such, the OTP if this method is used is reasonably secure.  If you're using U2F, rather than auth, then your phone is actually <em>more</em> secure.</li><li>If you're using auth and just storing the tokens on the yubikey, then yes, the phone messages result in a very marginal reduction in security (it's still better than storing the keys on the phone, since there's no secret to be surreptitiously stolen, but it's not as good as yubikey + phone, since it only requires getting into the phone and your text message application; in my case that's yet another layer, since I use Signal).</li></ol><br />Now, is it perfect?  No.  But it is definitely a significant improvement over the alternatives, both in convenience and security.  As far as the phone being SPOF, that was the case either way.  If they didn't have the phone number backup they'd still have access to the mail anyway as you've probably got it programmed on the phone.  There's not really any getting around it, other than to look into using the yubikey itself to unlock the phone (this is doable, but requires root and a fair bit of modification; you also risk locking yourself out quite thoroughly).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4454">SporkWitch</a> — Sat Aug 27, 2016 8:41 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Shadoninja]]></name></author>
<updated>2016-08-14T21:52:53+01:00</updated>
<published>2016-08-14T21:52:53+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8877#p8877</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8877#p8877"/>
<title type="html"><![CDATA[Gmail pretends to let you use Yubikey... why...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2395&amp;p=8877#p8877"><![CDATA[
I use my Yubikey with my LastPass and I love it. I use my Yubikey with GMail and.... well it is pointless. Google forces you to have your phone set up as a backup 2-factor auth. I have two Yubikeys and backup codes setup on my GMail and they still force the phone 2-factor to be setup. If you try to login and click the &quot;I don't have my security key&quot; button, you can continue using your phone as if the Yubikey was never part of the equation. This completely mitigates the security benefits of Yubikey. What makes this even worse is if you can get to my email account, you can reset my LastPass account too. So my phone is still the point of failure in my security setup at the moment even though I have upgraded to a dongle. <br /><br />Has anyone else noticed this?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4438">Shadoninja</a> — Sun Aug 14, 2016 9:52 pm</p><hr />
]]></content>
</entry>
</feed>