<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=474" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2010-01-27T00:11:07+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=474</id>
<entry>
<author><name><![CDATA[Jakob]]></name></author>
<updated>2010-01-27T00:11:07+01:00</updated>
<published>2010-01-27T00:11:07+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=474&amp;p=2006#p2006</id>
<link href="https://forum.yubico.com/viewtopic.php?t=474&amp;p=2006#p2006"/>
<title type="html"><![CDATA[Re: URGENT: Is it possible to fetch the static password?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=474&amp;p=2006#p2006"><![CDATA[
Assuming that I got you correctly, you're actually preempting some features that &quot;are in the oven&quot; at present. Among some other things <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /><br /><br />We will provide support for a static identity that can be read via the USB descriptors, where each Yubikey will be serialized with a unique number. This number will then reflect the serial number that is present on the sticker. For anyone who would prefer a more &quot;anonymous&quot; mode, this serial number can be hidden. We will however ensure that all devices are serialized at time of manufacturing.<br /><br />Maybe this simple function would be sufficient for the application you're calling for ? By simply using standard OS API calls, the serial number can then be read and used as a very basic identification means for a particular user. It probably goes without saying that this number can be spoofed, someone can make a fake Yubikey with the same number, a hook in the driver chain could mimic a genuine Yubikey etc. <br /><br />As an alternative, we'll provide support for challenge-response via API calls. This is a configurable option on a per configuration slot basis so anyone who don't want the feature can turn it off. This allows a client application to pro grammatically interact with the Yubikey, which is useful in certain configurations.<br /><br />As the question has been brought up, we're planning to test out the functionality with some selected customers. Please let me know if you have a particular application in mind and would like to participate. Please send me an e-mail at jakob at yubico dot com and give a short description of the use case and we'll provide a sample key with sample code when we have it available for beta testing.<br /><br />With the best regards,<br /><br />JakobE<br />Hardware- and firmware guy @ Yubico<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=83">Jakob</a> — Wed Jan 27, 2010 12:11 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Globan]]></name></author>
<updated>2010-01-26T20:15:37+01:00</updated>
<published>2010-01-26T20:15:37+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=474&amp;p=2005#p2005</id>
<link href="https://forum.yubico.com/viewtopic.php?t=474&amp;p=2005#p2005"/>
<title type="html"><![CDATA[URGENT: Is it possible to fetch the static password?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=474&amp;p=2005#p2005"><![CDATA[
Hi, <br /><br />I have a client who is interested in buying Yubikeys but he is already using a USB software lock on his software (they are software providers with 2000 customers) and wonders if it's possible to use yubikey as a software lock (dongle) as well. They fetch a security code from inside the usb lock, so down to my questions: <br /><br />Is it possible to do the same with yubikey? <br />As I understand, OTPs are generated when you push the button, but can it be generated in other way, i.e by a software command? If not, can we fetch static password?<br /><br />This would be a great solution to use yubikey both as it is (user authentication) and as software lock. <br /><br />If this is not possible today, is it something Yubico can plan for? <br /><br />I appreciate your answers.<br /><br />Cheers.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1035">Globan</a> — Tue Jan 26, 2010 8:15 pm</p><hr />
]]></content>
</entry>
</feed>