<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=78" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2008-06-03T23:44:46+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=78</id>
<entry>
<author><name><![CDATA[Jakob]]></name></author>
<updated>2008-06-03T23:44:46+01:00</updated>
<published>2008-06-03T23:44:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=78&amp;p=156#p156</id>
<link href="https://forum.yubico.com/viewtopic.php?t=78&amp;p=156#p156"/>
<title type="html"><![CDATA[Re: Can Yubikey be used to generate a long fixed password?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=78&amp;p=156#p156"><![CDATA[
Although one can argue that a static OTP would somewhat compromise the whole concept behind a hardware token, there are certain use cases where this makes sense. Quite a few people have asked about this feature.<br /><br />A 32-character password string that is resistant to a dictionary attack is not that bad after all. And best of all, you can use it to login to legacy systems supporting static passwords only.<br /><br />Therefore, effective from firmware version 1.3.0, we've added a &quot;sneak&quot; feature to support static OTPs by the means of a configuration flag.<br /><br />It is fully compatible with the current field layout with the difference that all dynamic fields (including the rnd16) are forced to a fixed value, in this case 0xff and 0xffff respectively. Therefore, the generated OTP remains the same every time.<br /><br />We've not updated the authentication server to support this feature yet, but as it will distinguish between a BAD_OTP and a REPLAYED_OTP, responses other than BAD_OTP can be considered ok.<br /><br />Jakob E<br />Hardware- and software guy @ Yubico<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=83">Jakob</a> — Tue Jun 03, 2008 11:44 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-06-03T17:25:55+01:00</updated>
<published>2008-06-03T17:25:55+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=78&amp;p=152#p152</id>
<link href="https://forum.yubico.com/viewtopic.php?t=78&amp;p=152#p152"/>
<title type="html"><![CDATA[Can Yubikey be used to generate a long fixed password?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=78&amp;p=152#p152"><![CDATA[
<strong>Q. </strong>Does Yubico have a solution available for me to change a static, fixed long password on the Yubikey. I would like the password to be statically set on the Yubikey and would like to be able to change it if needed.<br /><br /><strong>A. </strong>No, not right now. For long &amp; static passwords we encourage users to use MashedLife.com for that purpose:<br /><br />1. An admin creates/stores the static username/password that have access to a web site<br /><br />2. The admin &quot;shares&quot; the acct with users<br /><br />3. So the users can log on the web site w/o knowing the password to the site<br /><br />But this is a real need and we are talking w/ some business partners to see if they can do it, then we'll link to their solution from this forum.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Tue Jun 03, 2008 5:25 pm</p><hr />
]]></content>
</entry>
</feed>