Yubico Forum
https://forum.yubico.com/

Regarding lost/damaged YubiKey
https://forum.yubico.com/viewtopic.php?f=4&t=478
Page 1 of 1

Author:  network-marvels [ Mon Feb 08, 2010 12:23 pm ]
Post subject:  Regarding lost/damaged YubiKey

We received recently following questions over email where a customer was asking what if he lost his YubiKey.

Here are the answers:

    Q.1 What happens if the YubiKey is lost?

    Answer: The ability to provide access when user lost his YubiKey depends on the application/Website providing YubiKey based authentication. Many applications/websites allow user to assign multiple YubiKeys to his login account so that user can still access his account if he lost one of his YubiKeys. Some websites provides administrative/help-desk functionality where user can login to his account in case he lost his YubiKey.

    Yubico also provides Yubico Revoke Service (for Yubico online validation server) where an administrator can disable the lost key and also register a new key to the user.

    Q.2 What happens if the YubiKey is physically damaged?

    Answer: The key needs to be replaced. An administrator can replace the key. Also if the YubiKey stops working within one years of original delivery it is likely to be covered under Yubico Warranty.

    Q.3 What happens if there is a corruption of the data stored on the key?

    Answer: Regular data and files cannot be stored on the YubiKey. It is a strict authentication device. The authentication data stored in the key is protected against change by hashing mechanism so any unwanted changes would be discovered. If it would still happen, the YubiKey is then likely damaged and needs to be replaced (also see warranty above).

We hope this helps!

Author:  JH2007 [ Tue Aug 31, 2010 5:23 am ]
Post subject:  Re: Regarding lost/damaged YubiKey

Sorry network-marvels but I have to bust yer chops.
Your Q&A is very simple, and many of my original concerns on this issue are of concern.
Since I am a system admin., I don't want to wait for new Yubikeys to be shipped until I can check email/login to websites, etc.

Additional details/background on past discussions of this subject:
Dual usage Yubikey
viewtopic.php?f=6&t=287&p=1392#p1392
Winchester Password System should be mandatory for Yubikeys.
viewtopic.php?f=6&t=311&p=1452#p1452


Lastpass, now someone there obviously listened to our concerns and they offer a paid pro account where a person can have up to 5 yubikeys registered for use with a single account ID. (it's my opinion it has a been well designed for privacy and security)

Personally, I would tell people who ask "what happens if" that if they have any concerns to buy Yubikeys in pairs, and only use them with programs/websites that allows for 2 or more Yubikeys to be registered (per account) to grant access.

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/