<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=854" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2012-09-03T11:27:00+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=854</id>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2012-09-03T11:27:00+01:00</updated>
<published>2012-09-03T11:27:00+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=854&amp;p=3273#p3273</id>
<link href="https://forum.yubico.com/viewtopic.php?t=854&amp;p=3273#p3273"/>
<title type="html"><![CDATA[Re: Static Password Settings]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=854&amp;p=3273#p3273"><![CDATA[
Hello,<br /><br />In order to support legacy password systems, the Yubikey 2 supports user-triggered static password change. The function is designed for the specific use case of a traditional login system with a stricter password policy where the user is asked to change their password on a regular basis.<br /><br />The intended use case is like the following:<br />1. The user is asked to update their password.<br />2. The user enters their secret password. The user presses the Yubikey button and the current fixed password is yielded<br />3. The user is asked to enter the new password.<br />4. The user enters their secret password. The user presses and holds the Yubikey button for 10 seconds.<br />5. When released, a short tap updates the internal password with a new randomized one. The new OTP is sent.<br />6. The user is asked to confirm the new password.<br />7. The user enters their secret password. The user presses the Yubikey button again and the new password is sent.<br />8. The user completes the password change.<br /><br />As the change function has no protection against unauthorized usage, there is a danger that an unauthorized person can sabotage a user’s Yubikey by triggering this function.<br /><br />Thanks and best regards,<br />Samir.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Mon Sep 03, 2012 11:27 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[SamuelGE]]></name></author>
<updated>2012-09-01T00:49:18+01:00</updated>
<published>2012-09-01T00:49:18+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=854&amp;p=3266#p3266</id>
<link href="https://forum.yubico.com/viewtopic.php?t=854&amp;p=3266#p3266"/>
<title type="html"><![CDATA[Static Password Settings]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=854&amp;p=3266#p3266"><![CDATA[
Hi, <br /><br />I have just been looking at my YubiKey personalisation program on my Mac and come across a part in the settings titled 'Static Password Settings'. Under the title there is a tick box with 'Enable manual update using the button (YubiKey 2)'<br /><br />What does this mean/do?<br /><br />Thank you,<br />Sam<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2093">SamuelGE</a> — Sat Sep 01, 2012 12:49 am</p><hr />
]]></content>
</entry>
</feed>