<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=8&amp;t=75" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2008-09-13T14:14:25+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=8&amp;t=75</id>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-09-13T06:40:45+01:00</updated>
<published>2008-09-13T06:40:45+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=685#p685</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=685#p685"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=685#p685"><![CDATA[
Robert &amp; Phil, <br /><br />Agreed fully!<br /><br />Thanks<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Sat Sep 13, 2008 6:40 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Robert]]></name></author>
<updated>2008-09-13T14:14:25+01:00</updated>
<published>2008-09-12T09:32:23+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=683#p683</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=683#p683"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=683#p683"><![CDATA[
<div class="quotetitle">Massyn wrote:</div><div class="quotecontent"><br />Hi guys,<br /><br />I would propose that for developers, how about including the AES key printed on the invoice being included with the shipping?  I would not want to get it through the web, for the risk of someone hijacking my OTP and getting the AES key before me.<br /><br />For large quantities, I would prefer a secure https web delivery method, where 1 of the Yubikey's in the package should be a &quot;special&quot; one that is required to unlock the website, call it a bright shiny red Admin key, not for general use, simply for the admin page on Yubico.  When ordering a few hundred keys, having 1 extra for admin purposes wouldn't be a problem.<br /><br />Cheers<br /><br />Phil Massyn<br /></div><br /><br />I definitely agree to what Phil said. It can not be that someone can just use one or two OTP's of a YubiKey and get the full AES key. It doesn't matter by what means (https, PGP, etc)! That's just not secure, and we talk about security if we talk about the YubiKey. It would undermine the security of all YubiKey's out there.<br /><br />The proposal of Phil's is probable a feasible and secure way and it assures that only the receiver of one or a bunch of YubiKey's can get access to the original AES key's. The process described is pretty secure and it addresses single key handling as well as high volume handling with the 'red-key'.<br /><br />Of course, at the current state it might be that in some exceptions the 'current process' is applied. But for the future, a secure process needs to be implemented.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=242">Robert</a> — Fri Sep 12, 2008 9:32 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-09-11T19:10:34+01:00</updated>
<published>2008-09-11T19:10:34+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=676#p676</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=676#p676"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=676#p676"><![CDATA[
Folks, here is a new way, the web way of doing it here and now:<br /><br /><!-- l --><a class="postlink-local" href="http://forum.yubico.com/viewtopic.php?f=5&amp;t=185">viewtopic.php?f=5&amp;t=185</a><!-- l --><br /><br />Cheers<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Thu Sep 11, 2008 7:10 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[pablot]]></name></author>
<updated>2008-08-01T00:37:41+01:00</updated>
<published>2008-08-01T00:37:41+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=508#p508</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=508#p508"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=508#p508"><![CDATA[
<div class="quotetitle">paul wrote:</div><div class="quotecontent"><br />Yes, it is the way it works before Simon implements the state-of-art way of delivery. You can email your 2 OTPS as proof of possession and you GPG (or PGP) key to <!-- e --><a href="mailto:Support@Yubico.com">Support@Yubico.com</a><!-- e --><br /><br />Cheres  <img src="https://forum.yubico.com/images/smilies/icon_e_geek.gif" alt=":geek:" title="Geek" /><br /></div><br /><br />Ok, thank you. I've just sent the email.  <img src="https://forum.yubico.com/images/smilies/icon_e_biggrin.gif" alt=":D" title="Very Happy" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=146">pablot</a> — Fri Aug 01, 2008 12:37 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-07-31T02:33:24+01:00</updated>
<published>2008-07-31T02:33:24+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=505#p505</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=505#p505"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=505#p505"><![CDATA[
Yes, it is the way it works before Simon implements the state-of-art way of delivery. You can email your 2 OTPS as proof of possession and you GPG (or PGP) key to <!-- e --><a href="mailto:Support@Yubico.com">Support@Yubico.com</a><!-- e --><br /><br />Cheres  <img src="https://forum.yubico.com/images/smilies/icon_e_geek.gif" alt=":geek:" title="Geek" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Thu Jul 31, 2008 2:33 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[pablot]]></name></author>
<updated>2008-07-30T01:57:40+01:00</updated>
<published>2008-07-30T01:57:40+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=498#p498</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=498#p498"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=498#p498"><![CDATA[
Hi Simon, can I send you my GnuPG public key and a couple of OTP from two yubikeys so you can send me an ENCRYPTED email with the two AES keys?<br /><br />Thank you,<br />Pablo<br /><br />PS: please let me know your email address so I can email you.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=146">pablot</a> — Wed Jul 30, 2008 1:57 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[pablot]]></name></author>
<updated>2008-06-16T16:54:16+01:00</updated>
<published>2008-06-16T16:54:16+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=299#p299</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=299#p299"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=299#p299"><![CDATA[
<div class="quotetitle">Simon wrote:</div><div class="quotecontent"><br />To clarify, if anyone wants to get the AES key in their own yubikey, just send me an OTP for your device and we'll take care of it manually.<br /><br />This thread is about how to do this &quot;properly&quot; in the future.<br /><br />/Simon<br /></div><br /><br /><br />Ops!, I'm sorry, I do want my AES key and have sent you a PM with a OTP of my yubikey.<br /><br />pablot<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=146">pablot</a> — Mon Jun 16, 2008 4:54 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Massyn]]></name></author>
<updated>2008-06-16T03:21:58+01:00</updated>
<published>2008-06-16T03:21:58+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=291#p291</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=291#p291"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=291#p291"><![CDATA[
Hi guys,<br /><br />I would propose that for developers, how about including the AES key printed on the invoice being included with the shipping?  I would not want to get it through the web, for the risk of someone hijacking my OTP and getting the AES key before me.<br /><br />For large quantities, I would prefer a secure https web delivery method, where 1 of the Yubikey's in the package should be a &quot;special&quot; one that is required to unlock the website, call it a bright shiny red Admin key, not for general use, simply for the admin page on Yubico.  When ordering a few hundred keys, having 1 extra for admin purposes wouldn't be a problem.<br /><br />Cheers<br /><br />Phil Massyn<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=148">Massyn</a> — Mon Jun 16, 2008 3:21 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Simon]]></name></author>
<updated>2008-06-15T23:53:30+01:00</updated>
<published>2008-06-15T23:53:30+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=283#p283</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=283#p283"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=283#p283"><![CDATA[
To clarify, if anyone wants to get the AES key in their own yubikey, just send me an OTP for your device and we'll take care of it manually.<br /><br />This thread is about how to do this &quot;properly&quot; in the future.<br /><br />/Simon<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2">Simon</a> — Sun Jun 15, 2008 11:53 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[pablot]]></name></author>
<updated>2008-06-15T15:17:16+01:00</updated>
<published>2008-06-15T15:17:16+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=279#p279</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=279#p279"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=279#p279"><![CDATA[
While the https web page is a very convenient solution, I think the email/OpenPGP solution is secure, practical and fast option in order to get our keys fast, while a better solution is developed.<br /><br />Personally I would love to get my AES key as soon as possible because I cannot make any developement without loosing my actual key and all the yubico online services.<br /><br />Please consider the email/OpenPGP in the meantime. By the way, can I get my AES key NOW by any other method?. I now, I'm a bit anxious! <img src="https://forum.yubico.com/images/smilies/icon_e_wink.gif" alt=";-)" title="Wink" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=146">pablot</a> — Sun Jun 15, 2008 3:17 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Gerco]]></name></author>
<updated>2008-06-11T16:44:36+01:00</updated>
<published>2008-06-11T16:44:36+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=237#p237</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=237#p237"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=237#p237"><![CDATA[
<div class="quotetitle">Simon wrote:</div><div class="quotecontent"><br />We are somewhat skeptic to the web service approach for AES key distribution, since it means that anyone who gets hold of your yubikey for a minute or two can retrieve the AES key for it.  Not good for security...  I do understand it is the best for quick testing though.<br /></div><br />You missed the part about requiring to enter a password or code, set at purchase or generated and provided by mail with the keys themselves, to verify that the one logging in with the key is the same person as the one who made te purchase. That solves that security issue and will not allow anyone with only the yubikey to retrieve the key.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=99">Gerco</a> — Wed Jun 11, 2008 4:44 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[aha42]]></name></author>
<updated>2008-06-10T00:44:28+01:00</updated>
<published>2008-06-10T00:44:28+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=211#p211</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=211#p211"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=211#p211"><![CDATA[
You only need to download the file with AES keys once (for a batch), so could it not be possible to allow only one successful https download?<br /><br />In the case some black hat manage to borrow a YubiKey from you before you did get chance to download yours <em>you will know</em> since you can not get the AES keys.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=108">aha42</a> — Tue Jun 10, 2008 12:44 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Simon]]></name></author>
<updated>2008-06-09T08:31:31+01:00</updated>
<published>2008-06-09T08:31:31+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=187#p187</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=187#p187"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=187#p187"><![CDATA[
We are somewhat skeptic to the web service approach for AES key distribution, since it means that anyone who gets hold of your yubikey for a minute or two can retrieve the AES key for it.  Not good for security...  I do understand it is the best for quick testing though.<br /><br />Right now we don't have easy access to connect the yubikey OTP with the e-mail of the person who bought it, so we can't do an automated e-mail ping either.  But we could fix this, but it will increase time&amp;costs at personalization time for us.<br /><br />/Simon<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2">Simon</a> — Mon Jun 09, 2008 8:31 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[James]]></name></author>
<updated>2008-06-06T03:27:55+01:00</updated>
<published>2008-06-06T03:27:55+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=174#p174</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=174#p174"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=174#p174"><![CDATA[
I like the simple HTTPS page for small orders too. Seems like it would be the easiest and cheapest to implement and require the least amount of maintenance once the system is up and running. <br /><br />If having the keys available on an internet accessible web server is not an option due to security reasons, then I would vote for the 1st suggested option of the OpenPGP protected text file being sent via email. I don't favor the CD option because I have received CD/DVDs in the mail and they sometimes arrive broken or scratched and this is when they are mailed to me from a place close to me. I have a feeling the odds of a CD arriving to me damaged when shipped from the other side of the world will be greater.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=87">James</a> — Fri Jun 06, 2008 3:27 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Henrik.Schack]]></name></author>
<updated>2008-06-05T20:40:08+01:00</updated>
<published>2008-06-05T20:40:08+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=75&amp;p=173#p173</id>
<link href="https://forum.yubico.com/viewtopic.php?t=75&amp;p=173#p173"/>
<title type="html"><![CDATA[Re: AES Key Distribution, how do you want it?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=75&amp;p=173#p173"><![CDATA[
Yes HTTPS webpage would be nice.<br />And very easy to implement <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":-)" title="Smile" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=111">Henrik.Schack</a> — Thu Jun 05, 2008 8:40 pm</p><hr />
]]></content>
</entry>
</feed>