| Yubico Forum https://forum.yubico.com/ | |
| Can a yubikey replace the paypal security key? https://forum.yubico.com/viewtopic.php?f=16&t=617 | Page 1 of 1 | 
| Author: | cire1425 [ Thu Dec 30, 2010 5:15 am ] | 
| Post subject: | Can a yubikey replace the paypal security key? | 
| Is it possible to replace the paypal security key with the yubikey in OATH-HOTP mode set for 6 digits? | |
| Author: | Jafo_Jeeper [ Sat Feb 05, 2011 1:35 am ] | 
| Post subject: | Re: Can a yubikey replace the paypal security key? | 
| I'm curious about this one, too... | |
| Author: | cornelinux [ Mon Feb 14, 2011 10:42 pm ] | 
| Post subject: | Re: Can a yubikey replace the paypal security key? | 
| Hi there, very obiously it is not possible due to two facts: 1. it depends on paypal what backend they are using. So the question is, if they would support the yubikey, integrate and chip it. 2. Paypal uses verisign keys, which are not oath compliant but use some unknown 3DES algorithm to calculate the one time password Kind regards Cornelius | |
| Author: | Jakob [ Tue Feb 15, 2011 10:26 pm ] | 
| Post subject: | Re: Can a yubikey replace the paypal security key? | 
| Since quite recently - yes you can. http://www.yubico.com/vip At present, the keys are sent out pre-configured so current keys cannot be updated with a valid VIP key. We'll see what the future will give us  Best regards, JakobE Hardware- and firmware guy @ Yubico | |
| Author: | cornelinux [ Tue Feb 15, 2011 11:33 pm ] | 
| Post subject: | Re: Can a yubikey replace the paypal security key? | 
| Only learned about it today... So good to hear, that this is possible with a well defined algorithm... What about the HMAC key - I guess it is transferred to symantec in a secure manner. Would it be possible to also get the hmac key, so that one could use the OATH token also with other applications? Kind regards Cornelius | |
| Author: | Jakob [ Thu Feb 17, 2011 7:38 pm ] | 
| Post subject: | Re: Can a yubikey replace the paypal security key? | 
| The HMAC key is proprietary to Symantec so that cannot be retreived. However, the second configuration is open for your own needs so please feel free to assign your own HMAC key there to be used with other applications. Best regards, JakobE Hardware- and firmware guy @ Yubico | |
| Author: | cornelinux [ Thu Feb 17, 2011 9:13 pm ] | 
| Post subject: | Re: Can a yubikey replace the paypal security key? | 
| Dear Jakob, what does proprietary to symantec mean. Does Yubico generate the HMAC and ship it to symantec or is it vice versa? Or does symantec generate the HMAC, store it to the yubikey and ship the yubikeys (via you?) This would make sence - since I think they (former verisgn) are running the backend? Kind regards Cornelius | |
| Author: | pine [ Sat Feb 26, 2011 5:58 am ] | 
| Post subject: | Re: Can a yubikey replace the paypal security key? | 
| As the page at http://www.yubico.com/vip suggests, please do check with PayPal before purchasing one if you intend to tie it with PayPal. Besides Denmark, APAC is not covered under PayPal VIP program according to PayPal Customer Service. It looks like only US, Canada, and limited European countries are under VIP coverage. On the other hand eBay works with my VIP token from my APAC account, but then it is another device not Yubikey, so I can't be sure the VIP-enabled Yubikey works as well for Asian countries. It will be great if PayPal supports VIP globally   | |
| Page 1 of 1 | All times are UTC + 1 hour | 
| Powered by phpBB® Forum Software © phpBB Group https://www.phpbb.com/ | |