Yubico Forum
https://forum.yubico.com/

Automatic navigation - poll
https://forum.yubico.com/viewtopic.php?f=4&t=275
Page 1 of 1

Author:  Jakob [ Wed Feb 25, 2009 3:12 am ]
Post subject:  Automatic navigation - poll

The automatic navigation feature is a bit of an unofficial gizmo feature that was implemented in an early stage. Although it is a pretty cool feature, we've not promoted it due to some issues with it.

Primo - As we emit all keystrokes, not just the "safe" modhex ones, we are subject to keyboard layout variations. An URL that works on a US keyboard may very well not work on a German one as the scan codes maps to different keys - www.yubico.com would be www.zubico.com :)

Secundo - The feature is Windows specific and as we claim that the Yubikey works on all platforms, this feature somewhat invalidates the statement.

Tertio - We make a "reasonable delay" after enumeration until the point we emit the URL. This "reasonable delay" is for example too short at the first insertion when the hardware is installed. Another issue when we now added support for pre-boot enumeration is that the URL string gets sent out nowhere at that point, potentially flooding the BIOS setup with some garbage.

Quarto - The feature in can in theory open up for some subtle attacks where "rougue keys" can launch bad things or go to bad sites, just like the highly criticized "CD autorun" feature.


There are a few more things, but in summary - the feature really does not work in a practical setting. That's life...

We're going through some validation stages and security reviews and feel very tempted to simply delete the feature due to the reasons listed above. But I very much know that there are quite a few people who really likes the feature. I somewhat guess it is more for personal use than for "professional" settings.

So the question is - what do you all say ? Will we get a swarm of upset users or shall we keep it "as is" in a kind of unsupported way where you explicitly need to enable the feature if you want it ?


Regards,

Jakob E
Hardware- and firmware guy @ Yubico

Author:  eduqate [ Wed Feb 25, 2009 11:34 am ]
Post subject:  Re: Automatic navigation - poll

As a new user, I didn't know about automatic navigation, a search of the forums didn't enlighten me and being Windows only is a negative for me so I'd say drop it.

You say it does not work in a practical setting, which sounds like a second reason for dropping it.

Ed

Author:  Dick [ Wed Feb 25, 2009 8:14 pm ]
Post subject:  Re: Automatic navigation - poll

Although the change that you've made in the latest firmware release to require a password to program/reprogram the auto-navigation would seem to resolve "Quarto", the first three issues remain.

Another downside is that having auto-navigation enabled interferes with multi-purpose/multi-site use. I noticed this with the YK that I purchased from MashedLife which wanted to take me to that website every time that I plugged it in. It would have been awkward to use the same YK for another purpose such as, for example, OpenID or even to log into this forum. While that might sell more YKs, it could inhibit adoption as a multi-use device.

Dick

Author:  James [ Thu Feb 26, 2009 3:32 am ]
Post subject:  Re: Automatic navigation - poll

If the feature is off by default and requires a password to enable it then I would say keep it unless it is going to require significant resources to maintain it in future firmware builds. In my opinion the more options available the more flexible the device will be. If a person manually enables that feature on their Yubikey then they will most likely know its limitations. That feature may prove useful for someone in their specific environment and be the difference between them going with a Yubikey or not. That being said I personally don't use the auto navigation feature and wouldn't miss it if it is removed.

Author:  Massyn [ Thu Feb 26, 2009 10:32 pm ]
Post subject:  Re: Automatic navigation - poll

You have to draw the line somewhere. I didn't know of this feature until I saw the option in the personalization tool. From what everyone has said here, I don't think this is something that should stay. It is too restrictive, and prone to misuse. Imagine a company deploys this feature, allowing employees to automatically log on through their secure SSL VPN solution using the YK with auto navigate feature. If the YK gets lost or stolen, without even knowing the URL, Mr Hacker just has to plug the YK in, press the button, and he's logged on.

In my opinion, stick to your core business, which is authentication - not auto navigation.

Cheers

Phil

Author:  JH2007 [ Wed Mar 25, 2009 4:47 am ]
Post subject:  Re: Automatic navigation - poll

I knew of this feature before I received a Yubikey.
I know that it had some problems under some OSes.
I don't hear of any discussion about using it lately.
So, I vote for dumping it all together.

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/