<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1343" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-03-19T11:04:08+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1343</id>
<entry>
<author><name><![CDATA[Tom]]></name></author>
<updated>2014-03-19T11:04:08+01:00</updated>
<published>2014-03-19T11:04:08+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1343&amp;p=5067#p5067</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1343&amp;p=5067#p5067"/>
<title type="html"><![CDATA[Re: Yubico Authenticator Desktop - Feature Request]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1343&amp;p=5067#p5067"><![CDATA[
Hello Morph,<br /><br />The scenario you describe is possible. Unfortunately this is not simple to address because of how the Yubikey works internally. The applet on the Yubikey is just sitting there and it is not active until a request comes in, so we cannot implement easily a check and using the internal clock wont be very simple.<br /><br />However, what you can do is set a password to protect your applet. Just click the FILE menu and hit Change Password. This will require you to unlock the applet before it can be used (you should not unlock the applet on un-trusted computers.)<br /><br />Currently we cannot ask for user's touch on this applet, but we are working on this for future release.<br /><br />Tom.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2195">Tom</a> — Wed Mar 19, 2014 11:04 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Morphlin]]></name></author>
<updated>2014-03-19T02:46:00+01:00</updated>
<published>2014-03-19T02:46:00+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1343&amp;p=5064#p5064</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1343&amp;p=5064#p5064"/>
<title type="html"><![CDATA[Yubico Authenticator Desktop - Feature Request]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1343&amp;p=5064#p5064"><![CDATA[
Hello,<br /><br />Been playing with this app (instead of studying...) and I reaaaaly love it. It's kind of exactly what I was waiting for!!<br /><br />I just would to make a feature request. Tom, let me know if you guys are going to consider.<br /><br />I was thinking that before the applet just gives to the desktop app TOTPs for the current time, that it requires the touch of the button. <br /><br />Since the running computer could be compromised, it could ask the applet to generate all future TOTPs really quickly (unless a specific protection is implemented inside the applet). So by asking the user to press the button before generating new TOTPs to the desktop app, it would prevent generating future TOTPs that could be used by an attacker later on.<br /><br />Thanks<br /><br />Morph<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2047">Morphlin</a> — Wed Mar 19, 2014 2:46 am</p><hr />
]]></content>
</entry>
</feed>