<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=3&amp;t=419" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2009-10-19T10:10:40+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=3&amp;t=419</id>
<entry>
<author><name><![CDATA[olov]]></name></author>
<updated>2009-10-19T10:10:40+01:00</updated>
<published>2009-10-19T10:10:40+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=419&amp;p=1835#p1835</id>
<link href="https://forum.yubico.com/viewtopic.php?t=419&amp;p=1835#p1835"/>
<title type="html"><![CDATA[Re: Time delta server project]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=419&amp;p=1835#p1835"><![CDATA[
<div class="quotetitle">fortean wrote:</div><div class="quotecontent"><br />OTOH, one might argue that now a cracker has 4 OTPs from the same key so in effect it is LESS secure.<br /></div><br />Interesting point, from this perspective it might be good to always validate the first<br />OTP against the validation server before the next OTP is requested. It might though<br />add some inconvenience for the user who needs to wait for the validation process<br />before the next OTP can be entered. <br /><div class="quotetitle">fortean wrote:</div><div class="quotecontent"><br />If you want to protect users against theft of their keys, simply add a second factor, e.g. a pincode, passphrase, mandatory client side certificate, TAN code etc. etc.<br /></div><br />Yes, this is certainly an option. <br /><br />Regards, <br />/Olov<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=911">olov</a> — Mon Oct 19, 2009 10:10 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[fortean]]></name></author>
<updated>2009-10-16T14:31:54+01:00</updated>
<published>2009-10-16T14:31:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=419&amp;p=1828#p1828</id>
<link href="https://forum.yubico.com/viewtopic.php?t=419&amp;p=1828#p1828"/>
<title type="html"><![CDATA[Re: Time delta server project]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=419&amp;p=1828#p1828"><![CDATA[
<div class="quotetitle">olov wrote:</div><div class="quotecontent"><br />Hi Henk,<br /><br />Thanks a lot for your feedback. [...] True. I'll also add an example interface where the OTPs are supplied in the order of the user's pin code. This provides at least some protection for a stolen key as well as added security against eavesdropping since the OTPs will be transmitted in unknown order over Internet.<br /></div><br /><br />OTOH, one might argue that now a cracker has 4 OTPs from the same key so in effect it is LESS secure. <br /><br />If you want to protect users against theft of their keys, simply add a second factor, e.g. a pincode, passphrase, mandatory client side certificate, TAN code etc. etc.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=682">fortean</a> — Fri Oct 16, 2009 2:31 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[olov]]></name></author>
<updated>2009-10-13T09:59:54+01:00</updated>
<published>2009-10-13T09:59:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=419&amp;p=1826#p1826</id>
<link href="https://forum.yubico.com/viewtopic.php?t=419&amp;p=1826#p1826"/>
<title type="html"><![CDATA[Re: Time delta server project]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=419&amp;p=1826#p1826"><![CDATA[
Hi Henk,<br /><br />Thanks a lot for your feedback. <br /><br /><div class="quotetitle">fortean wrote:</div><div class="quotecontent"><br />The interface currently does not work with Yubidrone (my G-phone's Yubikey emulation), as I have to switch between 2 apps (Yubidrone and the browser) which currently takes too much time. However, I will (of course) do my very best to circumvent this in some later version of Yubidrone <img src="https://forum.yubico.com/images/smilies/icon_cool.gif" alt="8-)" title="Cool" />.<br /></div><br /><br />The allowed timespan between multiple OTPs is set to a value, currently 4 seconds. Maybe that's a bit to tight. I hope to gather some statistics on the demo site in order to come up <br />with a reasonable default value for this timespan. <br /><br /> <div class="quotetitle">fortean wrote:</div><div class="quotecontent"><br />Also: this type of 'extra' protection does not help against theft. Indeed, it may even provide a false sense of security; the fact that one has to enter 3 OTP's may look impressive, but if one stole my key, he could simply press the key three times instead of once. I can't underwrite your statement that this is more secure than just pressing the key once, perhaps you'd care to explain this?<br /></div><br /><br />True. I'll also add an example interface where the OTPs are supplied in the order of the user's pin code. This provides at least some protection for a stolen key as well as added security against eavesdropping since the OTPs will be transmitted in unknown order over Internet. <br /><br />Best Regards, <br />Olov<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=911">olov</a> — Tue Oct 13, 2009 9:59 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[fortean]]></name></author>
<updated>2009-10-12T18:09:10+01:00</updated>
<published>2009-10-12T18:09:10+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=419&amp;p=1825#p1825</id>
<link href="https://forum.yubico.com/viewtopic.php?t=419&amp;p=1825#p1825"/>
<title type="html"><![CDATA[Re: Time delta server project]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=419&amp;p=1825#p1825"><![CDATA[
<div class="quotetitle">olov wrote:</div><div class="quotecontent"><br />A reference implementation for using YubiKey time stamps to improve<br />security is started. Feedback on the demo server is most welcome. Especially on how the interface is perceived from a user convenience and security perspective.<br /></div><br /><br />Hey, Olov,<br /><br />nice work!<br /><br />The interface currently does not work with Yubidrone (my G-phone's Yubikey emulation), as I have to switch between 2 apps (Yubidrone and the browser) which currently takes too much time. However, I will (of course) do my very best to circumvent this in some later version of Yubidrone <img src="https://forum.yubico.com/images/smilies/icon_cool.gif" alt="8-)" title="Cool" />. <br /><br />A remark: if we were forced to use this method regularly, we would exhaust the key much faster  <img src="https://forum.yubico.com/images/smilies/icon_eek.gif" alt=":shock:" title="Shocked" /><br /> <br />Also: this type of 'extra' protection does not help against theft. Indeed, it may even provide a false sense of security; the fact that one has to enter 3 OTP's may look impressive, but if one stole my key, he could simply press the key three times instead of once. I can't underwrite your statement that this is more secure than just pressing the key once, perhaps you'd care to explain this? <br /><br />Thanks and kind regards,<br />--<br />Henk<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=682">fortean</a> — Mon Oct 12, 2009 6:09 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[olov]]></name></author>
<updated>2009-10-12T11:48:59+01:00</updated>
<published>2009-10-12T11:48:59+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=419&amp;p=1824#p1824</id>
<link href="https://forum.yubico.com/viewtopic.php?t=419&amp;p=1824#p1824"/>
<title type="html"><![CDATA[Time delta server project]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=419&amp;p=1824#p1824"><![CDATA[
A reference implementation for using YubiKey time stamps to improve<br />security is started. The project is hosted at<br /><br /><!-- m --><a class="postlink" href="http://code.google.com/p/yubikey-timedelta-server-php/">http://code.google.com/p/yubikey-timedelta-server-php/</a><!-- m --><br /><br />A demo server of the project is available at<br /><br /><!-- m --><a class="postlink" href="http://timedelta.yubico.com">http://timedelta.yubico.com</a><!-- m --><br /><br />Feedback on the demo server is most welcome. <br />Especially on how the interface is perceived<br />from a user convenience and security perspective. <br /><br />-<br />Olov Danielson<br />Yubico<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=911">olov</a> — Mon Oct 12, 2009 11:48 am</p><hr />
]]></content>
</entry>
</feed>