<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=451" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2011-05-04T19:13:52+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=451</id>
<entry>
<author><name><![CDATA[odinsdream]]></name></author>
<updated>2011-05-04T19:13:52+01:00</updated>
<published>2011-05-04T19:13:52+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=451&amp;p=2679#p2679</id>
<link href="https://forum.yubico.com/viewtopic.php?t=451&amp;p=2679#p2679"/>
<title type="html"><![CDATA[Re: Yubikey and Facebook]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=451&amp;p=2679#p2679"><![CDATA[
&lt;em&gt;I want to believe such sites are secure, but how does one know? I am a little concerned about storing all of my passwords on a remote site. Now, that site has all my accounts and passwords. What if someone there goes bad? Is my information somehow encrypted so that only my yubikey can decode the site? How has this site and its security been verified?<br /><br />Sorry, I am just paranoid.&lt;/em&gt;<br /><br />All of your questions are answered already. LastPass encrypts and decrypts your passwords locally, not on their server. They store your encrypted password data on their servers to enable you to share password data across many browsers and mobile devices. That's not a security risk because they only have your encrypted data.<br /><br />When you add a YubiKey to the LastPass account it means that even if someone guesses your LastPass master password they cannot log in without your YubiKey present. You can optionally set up a list of trusted computers that LastPass will not require YubiKey more than once for. If you add a mobile device to your account you can lock it by MEID so that only your trusted mobile phones can even log in to your account.<br /><br />There is criticism of LastPass for not being open-source like Keepass or other options. To me personally, I'm willing to go with LastPass even given this criticism because of the support for YubiKey and the easy syncing between multiple browsers. This product has finally made it possible for me to have strong, unique passwords for all of my sites, and also to share them easily with my wife on all of our computers and phones. For the minimal cost, it really does work great.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1636">odinsdream</a> — Wed May 04, 2011 7:13 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Redhatter]]></name></author>
<updated>2011-03-13T10:20:24+01:00</updated>
<published>2011-03-13T10:20:24+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=451&amp;p=2609#p2609</id>
<link href="https://forum.yubico.com/viewtopic.php?t=451&amp;p=2609#p2609"/>
<title type="html"><![CDATA[Re: Yubikey and Facebook]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=451&amp;p=2609#p2609"><![CDATA[
<div class="quotetitle">alphageek wrote:</div><div class="quotecontent"><br />I got my yubikey as a Christmas present and think is an amazing piece of technology.<br /><br />I noticed there was an earlier discussion on using the yubikey with facebook, and the conclusion seemed to be that yuibikey does not support openid 2.0.<br /></div><br /><br />Why would a hardware crypto token need to support an online authentication standard like OpenID 2.0?  It's like expecting your computer monitor to support HTML5.  The YubiKey is just an input peripheral that generates OTPs according to a set of rules which may be checked by a remote system.  How the remote system uses the information obtained is entirely outside the realm of the YubiKey itself.<br /><br />There are a couple of OpenID providers that support the YubiKey such as Clavid (mentioned earlier), or you can set up your own (as I have done <a href="http://openid.longlandclan.yi.org" class="postlink">here</a>) that will let you use the YubiKey on any OpenID enabled site.<br /><br />I'm not sure of the specifics regarding FaceBook.  Never got involved with that site, and I'm happy to not be anywhere near it.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1526">Redhatter</a> — Sun Mar 13, 2011 10:20 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[StepnSteph]]></name></author>
<updated>2011-03-10T19:46:14+01:00</updated>
<published>2011-03-10T19:46:14+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=451&amp;p=2607#p2607</id>
<link href="https://forum.yubico.com/viewtopic.php?t=451&amp;p=2607#p2607"/>
<title type="html"><![CDATA[Re: Yubikey and Facebook]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=451&amp;p=2607#p2607"><![CDATA[
I found this thread via the search feature.<br /><br />Currently I'm using LastPass and a machine generated password to secure my Facebook login, and I just set up Clavid so that I can actually sign into my FB account away from home now.<br /><br />However, if it is at all possible to convince the people behind Facebook to directly support YubiKey then I would be one happy fella.  I've only had my keys for two or three days and I already love it.<br /><br />I'm flabbergasted that sites like Facebook still rely on the nonsense that's username and passwords.  This isn't Yubico's fault, I know, I'm just a bit frustrated at the other folks.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1571">StepnSteph</a> — Thu Mar 10, 2011 7:46 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[alphageek]]></name></author>
<updated>2010-01-07T00:42:56+01:00</updated>
<published>2010-01-07T00:42:56+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=451&amp;p=1944#p1944</id>
<link href="https://forum.yubico.com/viewtopic.php?t=451&amp;p=1944#p1944"/>
<title type="html"><![CDATA[Re: Yubikey and Facebook]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=451&amp;p=1944#p1944"><![CDATA[
I want to believe such sites are secure, but how does one know?  I am a little concerned about storing all of my passwords on a remote site.  Now, that site has all my accounts and passwords.  What if someone there goes bad?  Is my information somehow encrypted so that only my yubikey can decode the site?  How has this site and its security been verified?<br /><br />Sorry, I am just paranoid.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=995">alphageek</a> — Thu Jan 07, 2010 12:42 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Kuka]]></name></author>
<updated>2010-01-06T10:06:34+01:00</updated>
<published>2010-01-06T10:06:34+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=451&amp;p=1942#p1942</id>
<link href="https://forum.yubico.com/viewtopic.php?t=451&amp;p=1942#p1942"/>
<title type="html"><![CDATA[Re: Yubikey and Facebook]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=451&amp;p=1942#p1942"><![CDATA[
I used Yubikey + MashedLife or Lastpass to log in to any site.<br /><br />That's convenient and secure.<br /><br /> <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=938">Kuka</a> — Wed Jan 06, 2010 10:06 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[alphageek]]></name></author>
<updated>2010-01-06T01:48:52+01:00</updated>
<published>2010-01-06T01:48:52+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=451&amp;p=1939#p1939</id>
<link href="https://forum.yubico.com/viewtopic.php?t=451&amp;p=1939#p1939"/>
<title type="html"><![CDATA[Yubikey and Facebook]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=451&amp;p=1939#p1939"><![CDATA[
I got my yubikey as a Christmas present and think is an amazing piece of technology.<br /><br />I noticed there was an earlier discussion on using the yubikey with facebook, and the conclusion seemed to be that yuibikey does not support openid 2.0.  Is there any way to get openid 2.0 support with the key?  I have tried an openid account both here and at clavid. Is there some other error that I am making? Has someone gotten yubikey to allow a login to facebook?  I have been able to link accounts, but I cannot get any further.<br /><br />Thanks,<br /><br />Alphageek<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=995">alphageek</a> — Wed Jan 06, 2010 1:48 am</p><hr />
]]></content>
</entry>
</feed>