<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2398" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-12-08T17:19:45+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2398</id>
<entry>
<author><name><![CDATA[dain]]></name></author>
<updated>2016-12-08T17:19:45+01:00</updated>
<published>2016-12-08T17:19:45+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2398&amp;p=9210#p9210</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2398&amp;p=9210#p9210"/>
<title type="html"><![CDATA[Re: Confused beginner]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2398&amp;p=9210#p9210"><![CDATA[
You can find the full specification of the protocol here: <!-- m --><a class="postlink" href="https://developers.yubico.com/ykneo-oath/Protocol.html">https://developers.yubico.com/ykneo-oath/Protocol.html</a><!-- m --><br /><br />Once loaded onto a YubiKey the secret never leaves it.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=504">dain</a> — Thu Dec 08, 2016 5:19 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Mathieulh]]></name></author>
<updated>2016-12-07T14:27:03+01:00</updated>
<published>2016-12-07T14:27:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2398&amp;p=9207#p9207</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2398&amp;p=9207#p9207"/>
<title type="html"><![CDATA[Re: Confused beginner]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2398&amp;p=9207#p9207"><![CDATA[
<div class="quotetitle">ChrisHalos wrote:</div><div class="quotecontent"><br />Not sure I understand your question. The purpose of using the YubiKey is that the secret used to generate the TOTP codes remains stored on the secure element (rather than on your hard drive). To actually generate the code, the YubiKey has no knowledge of the current time (no internal battery), so it needs Yubico Authenticator (app) to calculate the code.<br /></div><br /><br />Is the secret sent to the Yubikey Authenticator app to calculate the final code/token or is the time sent to the Yubikey to perform the calculation?<br />If the former, then it is a very important design flaw/vulnerability as it would allow someone to steal the secrets stored on the Yubikey secure element as they are sent to the Yubikey Authenticator app by monitoring the USB and/or the NFC traffic, this could be further automated by a hidden daemon running on the target's phone/computer.<br /><br />Can you share more details the full process through which the token/codes get generated?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3608">Mathieulh</a> — Wed Dec 07, 2016 2:27 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2016-08-18T23:46:45+01:00</updated>
<published>2016-08-18T23:46:45+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2398&amp;p=8887#p8887</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2398&amp;p=8887#p8887"/>
<title type="html"><![CDATA[Re: Confused beginner]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2398&amp;p=8887#p8887"><![CDATA[
Not sure I understand your question. The purpose of using the YubiKey is that the secret used to generate the TOTP codes remains stored on the secure element (rather than on your hard drive). To actually generate the code, the YubiKey has no knowledge of the current time (no internal battery), so it needs Yubico Authenticator (app) to calculate the code.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Thu Aug 18, 2016 11:46 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[spindown]]></name></author>
<updated>2016-08-18T17:45:42+01:00</updated>
<published>2016-08-18T17:45:42+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2398&amp;p=8886#p8886</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2398&amp;p=8886#p8886"/>
<title type="html"><![CDATA[Re: Confused beginner]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2398&amp;p=8886#p8886"><![CDATA[
<div class="quotetitle">ChrisHalos wrote:</div><div class="quotecontent"><br />(1) Sites like LastPass, Salesforce, and others. If you don't need this, you could always program a different credential in slot 1 with the Personalization Tool<br /><br />(2) Assume you're referring to a YubiKey 4 or YubiKey NEO, if so, you can store and access authenticator credentials with Yubico Authenticator (these are time-based, which the YubiKey can't calculate without a companion app, Yubico Authenticator). You can store up to 30 credentials here, give-or-take (depending on factors like the length of the credential name being used).<br /><br />(3) <!-- m --><a class="postlink" href="https://www.amazon.com/gp/help/customer/display.html?nodeId=201962420">https://www.amazon.com/gp/help/customer ... =201962420</a><!-- m --><br /><br />Adding credentials is virtually identical to adding credentials with Google Authenticator, except the secrets are stored in the YubiKey and you're using Yubico Authenticator as the app instead.<br /></div><br /><br /><br />Hi Chris, thanks for the reply.<br /><br />For your last line, what is the point of using a Yubikey in this config then if the secrets are stored on the Yubikey?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4442">spindown</a> — Thu Aug 18, 2016 5:45 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2016-08-18T16:42:33+01:00</updated>
<published>2016-08-18T16:42:33+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2398&amp;p=8885#p8885</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2398&amp;p=8885#p8885"/>
<title type="html"><![CDATA[Re: Confused beginner]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2398&amp;p=8885#p8885"><![CDATA[
(1) Sites like LastPass, Salesforce, and others. If you don't need this, you could always program a different credential in slot 1 with the Personalization Tool<br /><br />(2) Assume you're referring to a YubiKey 4 or YubiKey NEO, if so, you can store and access authenticator credentials with Yubico Authenticator (these are time-based, which the YubiKey can't calculate without a companion app, Yubico Authenticator). You can store up to 30 credentials here, give-or-take (depending on factors like the length of the credential name being used).<br /><br />(3) <!-- m --><a class="postlink" href="https://www.amazon.com/gp/help/customer/display.html?nodeId=201962420">https://www.amazon.com/gp/help/customer ... =201962420</a><!-- m --><br /><br />Adding credentials is virtually identical to adding credentials with Google Authenticator, except the secrets are stored in the YubiKey and you're using Yubico Authenticator as the app instead.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Thu Aug 18, 2016 4:42 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[spindown]]></name></author>
<updated>2016-08-18T11:11:52+01:00</updated>
<published>2016-08-18T11:11:52+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2398&amp;p=8884#p8884</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2398&amp;p=8884#p8884"/>
<title type="html"><![CDATA[Confused beginner]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2398&amp;p=8884#p8884"><![CDATA[
Can someone help me and explain some basic questions<br /><br />1.) What exactly is OTP used for?<br /><br />2.) I have my key currently set up for OTP in slot 1, HMAC-SHA login for windows on config 2.<br /> Do I have to choose between HMAC-SHA or OATH-TOTP in config 2? I would love to be able to use all three.<br /><br />How does one go about setting up OATH 2FA for something like Amazon?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4442">spindown</a> — Thu Aug 18, 2016 11:11 am</p><hr />
]]></content>
</entry>
</feed>