Hi,
I have to say, that I'm really dissapointed by the yubikey 2.2, especially by the static password mode.
I ordered the Yubikey 2 to get a strong static password for my TrueCrypt encrypted System.
When I ordered, I got the impression that I can create really strong/long passwords. What I got is a result I don't trust in.
The following things are freaking me:
The strong password policy of the Personalization Tool (running in: Windows 7, 64 Bit) is useless, because:
- The special character seems to be a
! every time (an attacker could know this => weakening of the password)
- The settings "Mix upper and lower case" and "Mix alpha and numering" are completely useless, because, they influence only the first
5-6 chars and then, only
lower letters are following. And: Most of the time, only 1-2 numbers are used (both: an attacker could know this => weakening of the password)
Some examples:
!45CDtflhvvfuvhjduihduhdctelhgfrbuhthjirdtdcdhcfugcnvdrgfgtbeteun
This points let me doubt, that there is enough entropy at all into the whole password. Maybe, there are other statistical phenomena I can't find due to a lack of competence
here - but an experienced attacker may could!!
The following examples of
doubles seem to be support my theory:
!21RHbvtbtrkcb
ddnndjtifbktbcn
jjlhfvblnrcd
iitnfvhdj
vvfjgbvutvnckir
I analyzed those passwords in two ways:
Analyzing entropy in KeePass and using the Website
https://passwortcheck.datenschutz.chThe result: If I analyze the Password in KeePass, I get around 150-170 bits of entropy. BUT: If I delete those weak, guessable parts (see above!), I only get 110-115 bits. Thats far from what could be possible!
The result of the analyzation Website: It says, that
some of those Passwords are
WEAK (I got 20-60 from 100 possible points). I think: 'nuff said at this point...
I'm more and more unhappy with this device and even more so, because manual and website don't tell the truth in clear words.
You have to search the forum to find out, that Yubico blames CryptGenRandom for the results, but that is not OK - at least, as long yubico don't offers a manual or tutorial Video that show (
based on the current version of the Personalization Tool!!!), how to get really strong, high entropy passwords.
To cut a long story short:
At the moment I don't trust the Yubikey and won't use it for security related purposes. I get the impression, that the Yubikey was a waste of money for me and my purposes.