<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=1426" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-07-24T11:39:36+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=1426</id>
<entry>
<author><name><![CDATA[Josasp]]></name></author>
<updated>2014-07-24T11:39:36+01:00</updated>
<published>2014-07-24T11:39:36+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1426&amp;p=5432#p5432</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1426&amp;p=5432#p5432"/>
<title type="html"><![CDATA[Re: Windows logon using only first 12 in OTP?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1426&amp;p=5432#p5432"><![CDATA[
I understad, that does not validate against the 12 in OTP but rather the keys serial.<br />It may be fine, will definently check it out.<br /><br />Well I agree, it's not secure.<br />But neither are Windows-passwords, unless using user accounts in a domain, windows-passwords are stored locally and easily cracked with OphCrack or a similar utility.<br /><br />I don't consider Windows passwords to be any sercurity at all, since they can easily be decrypted.<br />They are however good for keeping away unwanted people from your workstation.<br /><br />However using windows passwords makes for little security and a minor inconvenience.<br />I would like to eliminate that incovenience totally, by for example integrating my yubikey.<br />Maybe even using a NFC reader <img src="https://forum.yubico.com/images/smilies/icon_e_wink.gif" alt=";)" title="Wink" /><br /><br />Best would be some BTLE solution, but that requireres harware support though.<br /><br />Tried FastAccess, facial recognition, worked great but is way to expensive for what i does. <br />25$ is too expensive for a so small problem.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2755">Josasp</a> — Thu Jul 24, 2014 11:39 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom]]></name></author>
<updated>2014-07-17T06:38:46+01:00</updated>
<published>2014-07-17T06:38:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1426&amp;p=5409#p5409</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1426&amp;p=5409#p5409"/>
<title type="html"><![CDATA[Re: Windows logon using only first 12 in OTP?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1426&amp;p=5409#p5409"><![CDATA[
That solution would not be secure, unless it uses the full OTP and validates against the Yubicloud.<br /><br />However, you can use the tool posted in this forum under the project section called &quot;yubikey monitor&quot;<br /><br />it is not secure, but it will protect you against you family members/friends (if the are not erudite in science) using the Yubikey serial number.<br /><br />Tom.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2195">Tom</a> — Thu Jul 17, 2014 6:38 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Josasp]]></name></author>
<updated>2014-07-15T05:38:45+01:00</updated>
<published>2014-07-15T05:38:45+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1426&amp;p=5405#p5405</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1426&amp;p=5405#p5405"/>
<title type="html"><![CDATA[Windows logon using only first 12 in OTP?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1426&amp;p=5405#p5405"><![CDATA[
Hi!<br /><br />Forgive me if this has been asked before, but I'm short on time and need a quick answer.<br /><br />Is there any option in avalible software to allow Windows login based only on the first 12 characters in the OTP?<br /><br />I understand that there is a login tool for challenge and response mode.<br />But that takes up one slot on my yubikeys and those are both busy.<br /><br />Ofcourse that does not provide the security of a challenge response or the that of the OTP.<br />But it's still better than the simple passwords we use today, atleast it won't be as easy as looking over someone's shoulder.<br /><br />Is there any software for that?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2755">Josasp</a> — Tue Jul 15, 2014 5:38 am</p><hr />
]]></content>
</entry>
</feed>