Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 8:46 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Wed Sep 24, 2014 2:18 pm 
Offline

Joined: Wed Sep 24, 2014 2:07 pm
Posts: 4
I recently purchased a Yubikey Standard but only just now understood some of the differences with the NEO.
My question is, would the NEO support holding (though any app, Authenticator or OATH/TOTP,...) the following all at once (since it's limited to 2 keys as well):
1. Windows Logon
2. LastPass
3. Dropbox
4. Gmail
5. Microsoft account

There are also some which are optional but nice to have:
- Lumia 630 (with Windows Phone 8.1)
- Facebook
- an extra Windows Logon (for my home server and personal PC)


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Thu Sep 25, 2014 1:17 am 
Offline

Joined: Sun Mar 24, 2013 11:07 am
Posts: 12
The short answer is, yes, you will be able to do most of what you want to do simultaneously with a single NEO. I have my NEO currently setup to do almost exactly what you're seeking.

Slot 1: YubiOTP (primarily for Lastpass)
Slot 2: Windows Logon

Using the YubiOATH applet installed on the NEO you can configure many OATH-compatable two-factor authentication services (even multiple accounts of each) at the same time including:

Dropbox
Google
Microsoft
GitHub
Evernote
Dreamhost

The new NEOs are apparently configured to make this process relatively easy, though it is still relatively time-consuming and takes a bit of effort; however, the new GUI-based tools (NEO Manager, Personalization Tool, etc) render the requirement to dive into command-line based configuration procedures largely unnecessary. I am quite sure that you will need to use the Yubico Authenticator app on your mobile device to generate the OATH codes, which appears to be currently available only on Android. You could also use the Yubico Authenticator Desktop version on your laptop to interface with the NEO and generate OATH codes, but you'd need to install the Desktop Authenticator on every computer you would expect to need to generate OATH codes to access your services.

You will not be able to use a NEO to setup 2FA on services such as LinkedIn or Apple, as they do not use OATH. Those services require an SMS-capable mobile phone number (and/or in the case of Apple a "verified" Apple device) to receive one-time use codes. From personal experience, I can tell you that LinkedIn and Apple only use your phone number for 2FA purposes, i.e. they do not post your 2FA number to your "profile".

Facebook does support OATH, but you have to cough up your mobile phone number to them first. Facebook, being Facebook, will add your mobile phone number to your "timeline" :roll:

I don't know exactly what you mean by your Lumia 630 as a "nice to have", but if you mean that you want to use your NEO to lock/unlock your phone I don't think that is possible. I also don't think you can use the NEO for "any" authenticator app (Google Authenticator, etc.). If you mean that you want to be able to use your NEO for 2FA access to your Lastpass vault via the Windows Phone Lastpass app, http://forum.yubico.com/viewtopic.php?f=26&t=1032 makes it appear that you can configure an NFC-capable Windows Phone to accept NDEF signals from your NEO. For Lastpass, this would occur via the YubiOTP you have configured in Slot 1 or Slot 2, not the YubiOATH applet. The Personalization Tool works great to set up this type of configuration. I can vouch that it works perfectly for Android.

If you purchase a NEO, you could configure one of it's slots for Windows Logon and use your existing Standard YubiKey to configure a different Windows Logon in one of it's slots. Alternately, I am pretty sure you could use your NEO for as many Windows Logons as you desire, but you would have to program all Windows Logons with the same HMAC-SHA1 secret. I am pretty sure this is possible because I deconfigured my Windows Logon before I updated from Windows 8 to Windows 8.1, re-formatted my hard drive, and then reconfigured my Windows 8.1 logon without reconfiguring my YubiKey. I just saved the HMAC-SHA1 secret in my Lastpass vault and re-used it after I reinstalled the Yubico Windows Logon setup assistant. I also have the same Windows Logon key configured on a seperate, backup YubiKey that I keep well guarded so I can still access my laptop if my NEO gets lost or damaged beyond repair.

I would strongly recommend you purchase an additional YubiKey of any type so you can have a backup Windows Logon. I am quite sure it would be very painful if you have Windows Logon via YubiKey enabled and you lose your only YubiKey.

If you want different HMAC-SHA1 secrets for each of your Windows Logons, it's going to cost you one YubiKey configuration slot per Windows Logon, and you'll run into an ever increasing requirement (or risk) of needing additional YubiKeys for backup. But, it will be more secure.

Welcome to YubiKey! It's an awesome tool and pretty fun to goof around with too!


Top
 Profile  
Reply with quote  
PostPosted: Fri Sep 26, 2014 8:44 am 
Offline

Joined: Wed Sep 24, 2014 2:07 pm
Posts: 4
Whooow, thank you for the detailed reply. In this case i will pretty soon buy a NEO and keep the old one as a backup.

In kinda guessed that Facebook isn't supported, and i'm not using Appple or LinkedIn.

LastPass for Windows Phone is rather limited, and after some research i've seen that indeed Unlocking the phone screen isn't possible because of platform limitations. I've worked as a C# developer in the past and maybe i'll make the time to find at least some intermediary/other option for securing my phone.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 10 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group