<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=1676" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-12-23T16:55:41+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=1676</id>
<entry>
<author><name><![CDATA[DavidW]]></name></author>
<updated>2014-12-23T16:55:41+01:00</updated>
<published>2014-12-23T16:55:41+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1676&amp;p=6613#p6613</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1676&amp;p=6613#p6613"/>
<title type="html"><![CDATA[Re: How do I keep our most important computers safe with Yub]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1676&amp;p=6613#p6613"><![CDATA[
If you have a Windows domain, I would issue logon certificates and store the user certificate in slot 9A of the PIV applet on a Yubikey NEO. To log on, the user inserts their NEO and enters the PIV PIN.<br /><br /><br />Static passwords are of limited use - all it takes is to open a text editor, press the button and you have a copy of the password. If you must use a static password (for example for a disk encryption password), the recommendation is that you store only part of the passwords in the Yubikey and type the rest.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3289">DavidW</a> — Tue Dec 23, 2014 4:55 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[DeanYoungblood]]></name></author>
<updated>2014-12-23T16:14:26+01:00</updated>
<published>2014-12-23T16:14:26+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1676&amp;p=6612#p6612</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1676&amp;p=6612#p6612"/>
<title type="html"><![CDATA[How do I keep our most important computers safe with Yubikey]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1676&amp;p=6612#p6612"><![CDATA[
Hi.<br /><br />I wish to use the Yubikey to keep my company's most important clients safe (executives, those who travel alot, etc). I was thinking something along this way:<br /><br />A locally non-administrative account to log in with (domain account). When there is a need for elevated permissions the user must use a local user in the local administrators group that has a static long password saved on the Yubikey. First I thought this was an OK idea until I realize that if the Yubikey is left in the computer all it takes is for an attacker is to know the user name of the local administrator account...<br /><br />Any tips from all of you Yubikey experts in the forum? The most important part is that the user must use a non-adminstrative account for the daily work but have the possibility to install programs as admin without needing to remember a long password. <br /><br />Thank you in advance!<br />/Dean Y<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3403">DeanYoungblood</a> — Tue Dec 23, 2014 4:14 pm</p><hr />
]]></content>
</entry>
</feed>