You Should Be Using Yubikeys!

2024 ж. 20 Мам.
785 805 Рет қаралды

I freakin' love Yubikeys. I switched to Yubikeys from Google Authenticator about a year ago, and I will never go back. Not only are they great for TOTP 2FA, but they do so much more! In this video, I try to cover it all, and probably screw up a few facts - but oh well - that's not the point. The point is - you should be using Yubikeys.
GET YOUR YUBIKEYS HERE: geni.us/GunRC
Product links (Amazon affiliate):
Tile: geni.us/VjQ2B
USB C to USB A adapter (for Yubikey 5Ci): geni.us/sYC9aN
Timecodes:
00:00 - Intro
02:18 - What are Yubikeys?
02:56 - What is 2FA?
04:40 - TOTP 2FA and Authenticator apps
06:12 - Why you should standardize on hardware security keys
06:47 - Why hardware keys are faster than authenticator apps
08:05 - Yubikey authentication beyond TOTP
08:30 - FIDO authentication
12:07 - Yubikey TOTP login example
13:00 - Yubico Authenticator overview
13:39 - Yubico Authenticator on iPhone example
14:32 - Yubikey U2F login examples
16:09 - Yubikey WebAuthn login example
16:31 - Yubikey Initial Setup
18:00 - Adding a TOTP token to Yubikey
19:51 - Adding TOTP tokens to multiple Yubikeys
22:51 - What if you lose your Yubikey?
25:17 - Adding a FIDO U2F token to Yubikey
28:37 - Using Yubikey for Windows Login
30:44 - Will the Yubikey work for any TOTP 2FA?
31:48 - Different Yubikeys available
----------------------
Buy me a beer! ko-fi.com/crosstalk
Or donate some Crypto! crosstalksolutions.com/contact/
Follow me on Twitter: @crosstalksol
Crosstalk Solutions - RECOMMENDED PRODUCTS: crosstalksolutions.com/recomm...
Crosstalk Discord: / discord
Amazon Wish List: a.co/7dRXc67
Crosstalk Solutions offers best practice phone systems and network/wireless infrastructure design/deployment. Visit CrosstalkSolutions.com for details.
Connect with Chris:
Twitter: @CrosstalkSol
LinkedIn: goo.gl/j2Ucgg
KZhead: goo.gl/g4G58M

Пікірлер
  • Wow, great video! Extremely informative, very well edited. This was exactly what I needed, thank you!

    @sdiggly@sdiggly3 жыл бұрын
  • Just ran across this video... All I can say is THANK YOU! You did an amazing job at laying out what Yubikeys not only are, but the demos were off the chain! Keep up the great work sir!

    @stevenhatcher6760@stevenhatcher67602 жыл бұрын
  • Very useful. I too had Yubikeys on hand waiting to understand how to use them. Multiple keys per account info helped alot.

    @APrintmaker@APrintmaker3 жыл бұрын
  • Thank you for your thorough summary of Yubikeys and set up. Bravo!!

    @carlode3593@carlode35933 жыл бұрын
  • Thanks, Chris! Using them already for about 3 years but managed to find some new things watching your video!

    @VirgilNicolae@VirgilNicolae3 жыл бұрын
    • Great to hear!

      @CrosstalkSolutions@CrosstalkSolutions3 жыл бұрын
  • Best balance between skimming over details to make it short and going way over time to make an exhaustive yet way too long video. Key points are covered. Points out of scope are stated as such. Points that have bigger implications and do need consideration at some point, are also made clear: things that make you think. Ideal balancing a critical yet confusing topic. Great vid.

    @grantrettke4851@grantrettke48512 жыл бұрын
  • Thank you for that great overview and answering all of my questions before i could even ask them.

    @olafschermann1592@olafschermann15923 жыл бұрын
  • Excellent! I just got the 5 NFC and answered EVERY question I had (spent hours trying to connect the dots)... Thanks a bunch!

    @contextmatters8243@contextmatters82432 жыл бұрын
  • "Scanning" the desktop screen by the desktop app is a pretty neat little usability hack! I haven't been using the app but now I'm sold on it 🤓

    @cbrunnkvist@cbrunnkvist3 жыл бұрын
  • Chris U have converted me to this yubikey, Thanks i feel much safer now , great vid

    @RETRO-CONSOLE-GAMER@RETRO-CONSOLE-GAMER3 жыл бұрын
  • Great video! Been using these for quite sometime, make sure to get an extra as backup as mentioned!

    @bewarako@bewarako3 жыл бұрын
  • Thanks Chris, great presentation. Have had a Yubikey for several years but only used it a few times so this was a great refresher.

    @JimPeiffer@JimPeiffer Жыл бұрын
  • Great video! I use the 5ci as primary and 5 NFC as secondary. I also have my PGP keys on my 5ci.

    @KrispyKrink@KrispyKrink3 жыл бұрын
  • The acting for the google Authenticator is top notch lol. Great video!

    @HouseDyson@HouseDyson3 жыл бұрын
  • Thanks for the incredibly useful video! You demystified a lot of information in a clear way!

    @terrancejhedrick@terrancejhedrick2 жыл бұрын
  • Thank you so much, this vid is amazing. You answered every question I had about the different application types. Simply brilliant! I am so thankful for you and you sharing your time.

    @sugafreebree@sugafreebree2 жыл бұрын
  • We have company issued Yubikeys for over 5 years and you are exactly right about how good they are. Even though I'm a very long time user, I am so glad you made this video. I have actually been wanting to use Yubikeys for my personal accounts, but hadn't invested the time to figure out how to set it up. So I've been using the MS and Google authenticators. But I prefer the yuibikey for the same reasons you cited. I was working in Germany a couple years ago and forgot my yubikey at home and needed access to our corporate VPN. We fortunately had an office a couple hours away and I was able to get a replacement through our IT. But I wasn't sure if I could setup a couple so I'd have a backup. I also wasn't sure about how to get it to work with a phone since my company issued yubikey is the USB A style. You really answered ALL my questions. I'm going to hit your link and pick up a few.

    @rexjuggler19@rexjuggler193 жыл бұрын
    • Yes, I am replying to my own post. I just received the 2x5NFC USB A's today that I ordered. I am even more positive now than before that this is what I needed as I spent a time over the weekend looking at the key capabilties. I am buying another 2 of them. I am getting a set for my wife for her to use for her accounts. As with most people, her security awareness is limited and it is pointless to preach about it to people. You just need to provide them with something secure and simple which this really does. It also means I can authorize all 4 on joint accounts so that if something happens to me she will have access to our accounts like gmail, 401k, banking etc. I work on numerous linux systems via putty and ssh and was very pleased I can use putty-cac as well even if the PC doesn't have a SmartCard slot. I tried it out earlier today on a few systems and works great. I had looked into SmartCard as an option about a year ago as a personal security solution, and dismissed it due to not working with phone and needing a reader among other shot-comings. I do use a CAC SmartCard for work, but only have the reader on my company issued laptop. This yubikey solves so many problems. I didn't know it had so many authentication choices. However, BEWARE - You need to get at least 2 and make sure you setup the additional keys or you WILL be locked out of your account if something happens to your main key. That should be made clear to someone considering this.

      @rexjuggler19@rexjuggler193 жыл бұрын
    • ​@@rexjuggler19 there are recovery codes in the event u lose your physical keys

      @wifienabled@wifienabled Жыл бұрын
  • I've always found Ubikey's own documentation to be fairly obtuse. Thanks for the clearest explanation yet.

    @mikeoreilly4020@mikeoreilly40203 жыл бұрын
  • Thanks for the demo and insight, have a great day

    @chrisumali9841@chrisumali98413 жыл бұрын
  • Love the 568B artwork on your wall.

    @gsawnv@gsawnv3 жыл бұрын
  • Funny, I just finished setting mine up last night! Ordered two more for my parents.

    @mdkv4@mdkv43 жыл бұрын
  • This a great video I really enjoyed it and it was very informative. I got one of these that was left over from a project at work. To pilot for a new customers 2FA implementation, seems very kool. I'm going to try and use the PIV deployment method with local active directory and a CA to use them as a smart card.

    @jordanlambuth362@jordanlambuth3623 жыл бұрын
  • I purchased 5 NFC and 5C NFC. I'm ready to set them up now that I lost my job. I wish I found you before and used your link. Great video!

    @Mopki3@Mopki33 жыл бұрын
  • Great video, thank you for giving this profound overview.

    @cristalballena-hotel@cristalballena-hotel3 жыл бұрын
    • Glad you enjoyed it!

      @CrosstalkSolutions@CrosstalkSolutions3 жыл бұрын
  • For your time codes to automatically put "chapters" on your timeline, you have to put a 0:00 time code in the list. Great video!

    @obiwan300@obiwan3003 жыл бұрын
    • yeah at 25:30 I was like, 'this is really good, but I gotta go'

      @betterwithrum@betterwithrum Жыл бұрын
  • Nice Video, I got a yubikey a few months ago but I wasn't using it to it's full potential, this video helped me understand what are the capabilities, thanks!

    @vorrac@vorrac2 жыл бұрын
  • Logged into KZhead with my YubiKey 5nfc usb-c to watch this video. Love YubiKeys and have a few, been using them since 2017.

    @Tinker_Thinker@Tinker_Thinker3 жыл бұрын
  • Second Yubikey just got here, third is on the way, love them.

    @kensmith7417@kensmith74173 жыл бұрын
  • Great video! It's worth noting that for most accounts, even if you miss typing in the code before it expires, as long as you know it, you can still enter it for some time (usually between 5 and 15 minutes). Obviously, as soon as it expires you can't see it anymore, but if you still remember it, you can still enter it.

    @iThinkergoiMac@iThinkergoiMac3 жыл бұрын
    • that's a hazard if u think about it

      @wifienabled@wifienabled Жыл бұрын
  • Now, this is neat. I never know those accounts are stored in the keys. I started using Authy last year because it can back-up my keys. But that means my secret codes are now on the cloud. I need that feature so I won't lose them whenever I reset my phone, which I do every time when it gets a major system upgrade. I don't lose my stuff easily, so having a key is better than having an app. Thank you for such an informative video.

    @adamkee97@adamkee973 жыл бұрын
  • Thanks Chris. Extremely informative video.

    @Davino.F.Nascimento@Davino.F.Nascimento3 жыл бұрын
  • You don't have to use the manual method to configure the same TOTP on all your YubiKeys, just switch between them while on the QR Code screen and enter the TOTP from the last key you configure to finish the respective service TOTP setup.

    @AmichaiRotman@AmichaiRotman2 жыл бұрын
  • Nice! Yes more like this. Timely too, I cleaned out a desk drawer and found some unused Yubikeys, they are getting put into place pronto.

    @mark_loveless@mark_loveless3 жыл бұрын
  • I’m a tech moron.... and was filled with dread at having to update my entire online security & password collection over various macs. This video has really helped ! I think I can now master this with a bit of time. Thanks 🙏

    @tadbarker7082@tadbarker70823 жыл бұрын
  • Thank you for making this informative video.

    @code8986@code89863 жыл бұрын
  • For TOTP you can use the QR code to program multiple Yubikeys simply program one and do not put the code from the key into the site, then insert your second one and add it there two and once you've programed the last one then enter the code into the site. As an alternative for having multiple keys for TOTP you may copy the code or QR image and store it in an encrypted file using tools like GPG/OpenPGP but that is an other subject, sort of... it would have been nice to cover the PGP functions of the Yubikey as well, may be that can be a future video :).

    @paulrobertmarino7623@paulrobertmarino76233 жыл бұрын
    • If you do this I don't believe you'd be able to revoke them individually, i.e. in case you lost one. You'd just have to remove and re-add the one you still have.

      @ahensley@ahensley Жыл бұрын
    • @@ahensley on the contrary, in that case if you lose one key you can just get a new one and feed it the existing TOTP seed (the original QR code/secret code). This way you don't have to invalidate existing TOTPs and redo them all over again in both new and old keys. (If there is a chance that you lost a key to someone who also has access to your passwords then the correct thing to do is actually invalidate existing TOTPs and redo them, not reuse existing seeds)

      @MitchKarajohn@MitchKarajohn Жыл бұрын
  • Really good content, thanks. If the key is stolen how difficult would it be to retrieve stored data?Are the data encrypted on the key?

    @dhanushkavithanage232@dhanushkavithanage2323 жыл бұрын
  • Very well done video, very informative, thank you so much

    @2kings3queens@2kings3queens3 жыл бұрын
  • Pristine clear and relevent tube. Thanks so much for such a nice review of the Yubikey products !

    @samrichardson9827@samrichardson98273 жыл бұрын
  • Dangit Chris! I’ve been thinking about doing this for a while. 5C NFC is ordered.

    @tedherman38@tedherman383 жыл бұрын
    • I may be overly concerned about hackers, but personally I would not go with anything that is wireless when security is concerned. Wireless just provides one extra weak link in the chain. When using radio technology, i.e.: "NFC" I do suggest making yourself aware of the exact radius of that particular radio transmission.

      @Inertia888@Inertia8883 жыл бұрын
    • @@Inertia888 Just the info I was looking for, thanks m8!

      @joshuanbray@joshuanbray3 жыл бұрын
    • @@Inertia888 got credit/debit card?

      @johnzoidberg9764@johnzoidberg97643 жыл бұрын
    • @@johnzoidberg9764 yes, I do. and I change my numbers every few months just in case it has been compromised.

      @Inertia888@Inertia8883 жыл бұрын
  • The only problem I have found with my YubiKey 5 NFC is that not all companies have changed their 2FA to use hardware Authorization... I wish YubiCo would update owners when they add new partners. Otherwise I love YubiKeys. They are about to come out with a Fingerprint YubiKey.

    @bennettrichards6851@bennettrichards68513 жыл бұрын
  • Awesome in depth explanation. Thank you

    @andrewdecatus5172@andrewdecatus51726 ай бұрын
  • Yes I bought two and they have been lying on my desk for two years as I tried to use and got all mixed up so hopefully I will be able to understand how to use (haven't listened to your clip yet).

    @daromee@daromee3 жыл бұрын
  • Is it recommended to buy two keys per user in an enterprise setting? Users are notorious for losing things 😅

    @JCtheMusicMan_@JCtheMusicMan_2 жыл бұрын
  • I absolutely love my YubiKey. The only downfall is the lack of support on many sites and web apps on the u2f protocol. I have tried many times to push these hardware keys on UniFi, Synology or others. But they rarely respond on the request, due to lack of the user base usage. The more people keep asking for these requests. The faster it will be taken into consideration.

    @dennisvanlith@dennisvanlith3 жыл бұрын
    • It’s a chicken or egg situation. No one wants to spend money on a piece of expensive junk that isn’t useful on more than a handful of sites that virtually no one uses. But no sites want to spend the resources to support Yubikey until more people buy them.

      @CCoburn3@CCoburn3 Жыл бұрын
  • Chris, I love your videos and especially this one, I saw it maybe more than 10 times....and if you see the rest of the comments, I purchased two using your links. But l figured that yubikeys are NOT faster than any Authenticator app and let me tell you and prove you why: I spend a whole evening trying to setup my 2 yubikeys, a 5Ci that I will use as a backup (got the idea from you) and a 5C Nano for my laptop. Later on, I decide to go to bed as I had to wake up early next day. So while I’m on my bed and using my phone trying to fell asleep, I decide to check my unify network, by using the “Unifi Network” application but, it asked my for a 2 step authentication. Unifi was one of the first setups I did with Yubikey since I saw that also on your video. So the fact that I had to get up, go to the living room that I had my laptop and next to it my 5Ci yubikey, so I will put it on my phone, in order to login to Unifi Network app, make me realize that yubikeys are NOT faster than my Authy app which was still installed on my phone but without my Unifi auth, since I removed it once I install the auth on my yubikey. I never made it to my living room since it wasn’t so important to go, but definitely made me question my self why I should move from Authy app, to a yubikey. More secure? Probably....but I feel like you want a house without glass windows just for the ONE chance that burglars brake the windows and get in your house. Nobody is building a house without glass windows, right? Although the possibility is always there, that burglars can get in. I hope you understand my point! I will try to use my yubikeys since I bought them, but I don’t know how convenient they are to be honest.

    @d3m3tr3s@d3m3tr3s3 жыл бұрын
  • Thanks for your easy to follow explanations

    @NitroSpaceYT@NitroSpaceYT Жыл бұрын
  • Thank you for the informative video. I was wondering if Google accepts Yubi Key for logging into Gmail, Google Account, etc.

    @matthewgrotke1442@matthewgrotke14423 жыл бұрын
    • Yes they do

      @MrWarrenJH@MrWarrenJH Жыл бұрын
  • I was constantly thinking "something in the background looks familiar, but I can't pinpoint it... Then my eye fell on the frame hanging next to your youtube reward button thing, and it clicked :D

    @mvl8209@mvl82093 жыл бұрын
    • @fuck google It's a wiring diagram for Ethernet cables www.google.com/search?q=ethernet+wiring+diagram&sxsrf=ALeKk00UdIyMZp6J_v1JjfzmBKeHK0SxRQ:1606463841336&tbm=isch&source=iu&ictx=1&fir=d3PlvGVMrC5arM%252CV-i5CBR7Nb_OJM%252C_&vet=1&usg=AI4_-kSGgTtbv7cz3tvqafq7529zknD0IA&sa=X&ved=2ahUKEwj3vO2UoKLtAhWNmKQKHeGNA50Q9QF6BAgCEFU&biw=1536&bih=722#imgrc=d3PlvGVMrC5arM

      @mvl8209@mvl82093 жыл бұрын
  • Your reenactment of using yukikeys was amazing and had me loling

    @theroachmotel@theroachmotel Жыл бұрын
  • Great info I'll be watching this video a few times to digest it all. Lots to consider.

    @kstaxman2@kstaxman22 жыл бұрын
  • Thank you, this took me over the top, I ordered Yubikeys (from your link, of course) for the family. One question remains. What happens with the lost backup Yubikey? Do you have to reset all the logins?

    @joselegarza148@joselegarza1483 жыл бұрын
    • Add a password to it. So if someone steals it, they'd have to know both the yubikey password and the account password.

      @bluekeybo@bluekeybo2 жыл бұрын
  • I'm just under two minutes into the video, I'm hopeful that this provides an answer about what to do if you break one, because I have been known to break tiny things like a USB Key, so that has been my biggest fear about them. I mean do you have a backup key? Can you make new backups if you need to use the backup because the original broke?

    @jeremybarlow2291@jeremybarlow22913 жыл бұрын
    • Yes if I were to use them I would and you can have multiple keys. Just like backups go for 3 keys one of which is off site but in a secure place. One on you, a replacement hidden somewhere in the house and another secured off site. He is actually wrong or misunderstood when it comes to having multiple token generators: just like backups you have a sequence of secure backup keys.

      @matthewsheeran@matthewsheeran2 жыл бұрын
    • Good

      @thomascruz210@thomascruz2102 жыл бұрын
    • You can't make a backup of a Yubikey, each Yubikey will forever remain a separate key with its own identity. What you can do is have several Yubikeys affiliated with a single account such that losing one means you can use the other. Any lost key needs to be manually removed from an account/website.

      @3QuaNiMiTyy@3QuaNiMiTyy Жыл бұрын
  • Best Yubikey video ever. I learned about this from a podcast but they just flew over the topic so fast I couldn't tell what to do with the damn thing; only that it was 2fa. Now I have a reason to buy a few to use for more security. I don't like using my phone for 2fa because I don't really trust the phone's os.

    @Lyunpaw@Lyunpaw3 жыл бұрын
  • Thats crazy, i placed an order for one this morning!

    @ethanm9421@ethanm94213 жыл бұрын
  • @16:46 - The collectable value on that special edition key dropped 99% the second you opened the original packaging. ;)

    @triularity@triularity3 жыл бұрын
  • When you talked with your yubikey engineer friend what did he say that made you use it.

    @YuriShevchouk@YuriShevchouk3 жыл бұрын
    • Probably that it's faster than using authenticator apps on your smartphone. Also that he showed him how to use it since he was unaware of how they worked

      @AlexsaurusRex@AlexsaurusRex3 жыл бұрын
  • If you kept it going till now you have all the respect that I can give

    @quddus404@quddus404 Жыл бұрын
  • Next year I buy this. Thanks for details review.

    @shetuamin@shetuamin3 жыл бұрын
  • You mentioned “losing” one of your Yubikeys. What’s the best practice for moving forward if you believe it to be truly lost or stolen? That would make a good video.

    @g-wizgeorge4454@g-wizgeorge44543 жыл бұрын
    • It depends on the account you lost. He briefly mentioned backup codes, I've seen that several times now that you get backup codes when you set up 2FA. Save those codes, and do not lose them. If you do, there may be no way back. I lost my Steam Authenticator, and had to contact support to get it straightened out. 2FA kind of worries me for that reason. Same problem with one time use texts, if you lose your number or your phone.

      @Gersberms@Gersberms3 жыл бұрын
    • Get two yubikeys and lock one of them up in a safe place, many sites will let you register multiple MFA devices. So if you lose one you can log in with the other key, delete the lost one and register the replacement. On sites that do not allow that they will have some sort of backup code or method. Put that info in a safe place.

      @ulbuilder@ulbuilder3 жыл бұрын
    • Simply buy ledger Nano s or Trezor T which only unlock after entering pin on the device. You only need to keep a 24 or 12 words backup if you lose your device, just buy another. They both offer Fido 2.

      @AmandeepSingh-oe4te@AmandeepSingh-oe4te3 жыл бұрын
    • I'd love an answer to that too. How do you invalidate a Yubikey if it is lost or stolen, to stop it from being used maliciously, or is the only way to manually remove it from all your accounts? Is there no way to say "I no longer have this key, remove all the accounts from it"?

      @Anaerin@Anaerin3 жыл бұрын
    • @@Anaerin Exactly - seems like you'd have to keep a list of everywhere it was registered and then go chasing them down manually. I know I won't do that (keep an up to date list)

      @ystebadvonschlegel3295@ystebadvonschlegel32953 жыл бұрын
  • I love using my Yubikeys and now they've brought out a model with a fingerprint reader, so... *TRIPLE* Factor for the win! Something you know, something you have, something you are!

    @beardymcbeardface69@beardymcbeardface693 жыл бұрын
  • been using a yubikey for years have a few of them. it's important to note if you set everything and then loss the key your going to have a problem. So its best to have two 1 you use and one you keep in a safe place with the same sites configured on it.

    @donovansobrero9553@donovansobrero95533 жыл бұрын
  • Thx Chris, Great Video, ... currently using it only for AAD auth, and I don't want to do without it anymore ...

    @andreasmahler3430@andreasmahler34303 жыл бұрын
  • I like the grumpy man typing google authenticator code.

    @daphbobo@daphbobo3 жыл бұрын
    • I use ubikey. I like it.

      @daphbobo@daphbobo3 жыл бұрын
  • Where can I get that shirt? Need!

    @AnimalFacts@AnimalFacts3 жыл бұрын
    • Same, LINK!!!!

      @domzzz1244@domzzz12443 жыл бұрын
    • I trust you recognize its from the Chromium browser's unreachable-location minigame? :-)

      @YadraVoat@YadraVoat3 жыл бұрын
    • probably not online...

      @cocotug0@cocotug03 жыл бұрын
    • TEEPUBLIC has several designs. I like this one www.teepublic.com/t-shirt/2053315-chrome-t-rex-dinosaur-rawr

      @ChrisHolt1@ChrisHolt13 жыл бұрын
    • make a stencil out of lego and ink stamp it on....

      @itchytastyurr@itchytastyurr3 жыл бұрын
  • Bought a YubiKey thanks to this video, with your affiliate link. Cheers Chris!

    @vtor@vtor3 жыл бұрын
  • Hi Chris thank for the wonderful explanation!

    @k7suraj@k7suraj2 жыл бұрын
  • Must have for Emails and Password managers. I just wished more websites would support security keys.

    @Agamerfr0zed@Agamerfr0zed3 жыл бұрын
    • Especially banks. Wish my bank and credit union would support it 😭

      @TheCowboy4000@TheCowboy40002 ай бұрын
  • I can’t look at that painting in the background without thinking of pixie sticks.

    @SDWNJ@SDWNJ3 жыл бұрын
    • It's the wiring order for a ethernet connector

      @kd0dbw@kd0dbw3 жыл бұрын
  • Just ordered a Yubikey looking forward to the setup and security with it!

    @Morning3309@Morning3309 Жыл бұрын
  • Excellent overview, thanks.

    @dab42bridges80@dab42bridges80 Жыл бұрын
  • I wish they had a screen for totp, with out having to plug in the device into a machine for those areas that we can’t install software nor plug usb into them

    @Nettechnologist@Nettechnologist3 жыл бұрын
    • I’ve used the NFC on some secure industrial machines

      @jimmymifsud1@jimmymifsud13 жыл бұрын
    • RSA hardware keys exist.

      @deusexaethera@deusexaethera3 жыл бұрын
    • @@deusexaethera Are you saying you can use RSA keys with Yubikey? I have extra RSA keys and didn't think this was possible

      @Nettechnologist@Nettechnologist3 жыл бұрын
  • It would be nice to see them integrate biometric authentication into it (an advantage of the smartphone) would also be nice if soft token MFAs got more into MFA push notifications for wearable devices. (Giving you the same one touch MFA experience as the ubikey).

    @sethalton205@sethalton2053 жыл бұрын
    • YubiKey Bio is coming soon. Has a built in fingerprint reader.

      @jhb5401@jhb54013 жыл бұрын
    • Or you could just use Secret Double Octopus and get rid of your password all together.

      @KyleJacksonplus@KyleJacksonplus3 жыл бұрын
  • Thank you So much for ur ti and support

    @Ravikumaryadav06@Ravikumaryadav06 Жыл бұрын
  • I now have my two 5NFC YubiKeys "Smart-Card Enabled" on both of my Macs meaning that the only way I can log onto either computer is to physically insert the Key into a USB port & enter the PIN. Passwords no longer work. Pairing my keys to each computer was easy peasy. Getting the "Smart-Card Enabled" on my computers required the same effort Generals in WWII had in planning the D Day invasion. Apple articles are incomplete & I never did find or talk with a Senior Tech Advisor that had ever even dealt with the codes required that need to be entered in Terminal. Either Passwords or the YubiKey can be used to log into a computer if "Smart-Card Enabled" isn't enabled which seems to me to defeat the purpose of YubiKeys. Yes, I've just subscribed & rang the notification bell. Warm Regards from Reno, Nevada.

    @azclaimjumper@azclaimjumper Жыл бұрын
  • I would love to be able to import my authy records into a yubi account.

    @jpenn727@jpenn7273 жыл бұрын
    • Youd basically just go into your accounts and disable your authy 2 factor authentication, then set them up again but on the Yubi account

      @VPC@VPC3 жыл бұрын
  • Up next: Built in yubikey into cellphone for additional $300 for easy access

    @vze4p6c2@vze4p6c23 жыл бұрын
    • 🤣👍

      @TheBurzhui@TheBurzhui3 жыл бұрын
    • Google has already done this. The Titan chip is in some Google phones.

      @bens1058@bens10583 жыл бұрын
    • The basic hardware is there already, in sim cards.

      @magfal@magfal3 жыл бұрын
    • Actually, many phones already have something like that build into it. So when your phone is unlocked, you can use it to log into systems. Both Android (since 7.x) and Apple. Apple and Windows laptops supposedly also support it. In Windows it's part of Windows Hello. In all cases I think they need to have a chip build in. Also Krypt Krypton might be an option.

      @autohmae@autohmae3 жыл бұрын
  • I was intently listening to you describe why I should be using a Yubikey and looking at the artwork on the wall behind you. I know I am really tired and need more sleep but I thought I'd keep watching as long as I could and then it hit me as to why that artwork looked so familiar. When you terminate enough network cables in your life that you can do it in your sleep, things like the T-568B standard just becomes like a white wall or a white ceiling. It's there but you just don't see it and yet you known it there.

    @FirstLastOne@FirstLastOne3 жыл бұрын
  • Thank you for explaining. I Just ordered a yubikey 5 nano yesterday. Unfortunately I only found your video today or I would have bought through your link.

    @justingreen8006@justingreen80063 жыл бұрын
  • What about push notification to auth app? I can accept a prompt in about 2 seconds by accepting it on my watch. Just saying...

    @ajbeau_au@ajbeau_au3 жыл бұрын
    • Convenience VS security

      @VPC@VPC3 жыл бұрын
  • "I had a half-dozen yubikeys on my desk that I never used until Yubico contacted me to join their affiliate program, but the affiliate program had no influence on my endorsement of their product."

    @jimk5145@jimk51453 жыл бұрын
    • 😂😂😂😂

      @KevinHoskinson647@KevinHoskinson647 Жыл бұрын
    • Looks like Yubidoobie is pumping loads of cash in influencing YT influencers. It’s Yubikey! wherever you go. Check out Rob Braxman for some real security tech.

      @GerryVeerman@GerryVeerman Жыл бұрын
    • Still doesn't change the fact that hardware 2FA is much more safer and reliable compared to software/SMS alternatives when used correctly.

      @cydia2020@cydia2020 Жыл бұрын
  • Excellent presentation. Thank you.

    @duaneatnofroth@duaneatnofroth2 жыл бұрын
  • Great and complete tutorial. Thanks!

    @SimXtreme6@SimXtreme62 жыл бұрын
  • Great video, but I'm not convinced it's better for personal use, you really can't beat something like 1password's cmd+/ (mac) or ctrl+/ (windows) key combo which fills your username, password, and when using OTP, the 2FA code when prompted. One and done. Also integrates into Safari and Chrome for iOS or Android. Truly a one-stop password app. Not to mention, it's stored in an encrypted vault, so it's shared between ALL your devices. Lastly, no limit on the number of sites you can use 2FA on. Yubikey seems good for large-scale 2FA implementations, but not for personal use... IMO

    @DonovanCYoung@DonovanCYoung3 жыл бұрын
    • I think a middleground is perfect. Use yubikey for 1password and let 1password handle all other 2fa. I just googled and think it should work. You'd have the best of both worlds imo.

      @liquicitizendirk2147@liquicitizendirk21472 жыл бұрын
    • I think Chris got this wrong in his video. I'm not an expert on this, but I spent some time researching this because I wanted to know the technical details. If you're looking to replace authenticator apps that generate TOTP codes, a Yubikey or similar device can actually be used for an unlimited number of services. The 25 slot limit is for "Resident Keys" which are used for entirely password-less authentication schemes.

      @paoloposo@paoloposo Жыл бұрын
  • This is a hard no for me, would be lost in a minute.

    @garethsnaim8174@garethsnaim81743 жыл бұрын
    • Did you not see the part where he lost his?

      @donpeer4477@donpeer44773 жыл бұрын
  • Thanks for your video. It was very informative. PS. Steam game plataform uses a TOTP, but only in its own application. And let's not forgget banks, but they're thier own class.

    @adrianreboredamartinez1073@adrianreboredamartinez10733 жыл бұрын
  • Chris, thank you for this video. Very educational on Yubikeys and why everyone should be using one.

    @eXsoR65@eXsoR653 жыл бұрын
  • Google Authenticator now lets you log in and migrate devices, I believe. Edit: it requires the old device, but you can scan a QR code from the old device using the new device to migrate to the new device.

    @evancjensen@evancjensen3 жыл бұрын
    • That's great news! Excellent update. Still...I would never go back because it can't do FIDO or other enhanced types of 2FA.

      @CrosstalkSolutions@CrosstalkSolutions3 жыл бұрын
    • @@CrosstalkSolutions I couldn't agree more! Just wanted to point it out.

      @evancjensen@evancjensen3 жыл бұрын
    • If you're lucky the old device hasn't suffered a hardware failure,fire,water damage,theft etc I had a charging port go on my Android phone and only realized by the end of the day that the thing wouldn't take a charge and had to literally make haste to get another old spare phone setup and migrate via QR . If I didn't notice it earlier I woulda been hosed pretty badly as I've got Google 2FA on pretty much everything.

      @djdrastic1@djdrastic13 жыл бұрын
    • All MFA apps allow you to migrate your accounts. All you need to know is backup/recovery codes that you were provided with the first time you signed in to the MFA app.

      @OlegObukhov@OlegObukhov3 жыл бұрын
    • @@OlegObukhov up until this year, Google Authenticator did not. You'd have to redo every account...

      @evancjensen@evancjensen3 жыл бұрын
  • Hmm... Doesn't leaving the key plugged into your PC with the app running kind of defeat the object? Not unlike leaving your password on a post-it note under your keyboard really :-0

    @matthewryan@matthewryan3 жыл бұрын
    • That’s why I prefer to use a password manager and have the yubikey work with the master password to access the manager.

      @warcorer@warcorer2 жыл бұрын
    • Doesn't the yubikey (at least some models) still require biometric authentication before it works even if plugged in?

      @adamyork2333@adamyork23332 жыл бұрын
    • It would still need to be tapped by your fingers to activate… but yes, this has crossed my mind as well. For that I personally would steer clear of the “leave-in” ones… though i think the concerns are irrational for most security threats.

      @word42069@word420692 жыл бұрын
    • @@warcorer نَيس

      @ADeeSHUPA@ADeeSHUPA Жыл бұрын
    • In fact no, and thats why things like the trusted platform module and ssh keys exist, its just a second factor so if somebody wanted to hack your account they need your password too, or the other way around if they have your password they would need to hack the pc too to get the login done, but the yubikey requires button confirmation before login so thats fixed too

      @hyperfluff_folf@hyperfluff_folf Жыл бұрын
  • Really excellent. Thank you so much

    @ikust007@ikust0073 жыл бұрын
  • I loved the drink part... Nice 👌

    @okbustaman@okbustaman3 жыл бұрын
  • Gotta love KZhead recommendation: Up next: Breaking FIDO: Are Exploits in There? From Black Hat In all honesty I'm still slightly skeptical. I personally still only use passwords, and don't login on computers that I don't own/control. if I'm ever out and going and need to login to my bank or something like that I just use no-machine to connect back to my server at home and login thought that. I'm still not sure how trustworthy a for profit authentication company can be, when you have major player like google joining on the standards. I don't think there's a major security issue, I just don't think it's mature enough, on one side Google is fucked up, on the other Google (and other major players) have too much to lose if they start loosing reputation, so I don't think they would mess with authentication, but who's to say Yubikey can be trusted to not fuck up their protocol and chips being fundamentally flawed. The issue I have with all those passwords and double, triple checking of identity is that at the end they tend to try and make it easier to actually authenticate, and people end up using a 4 digit pin set to 0000, 1111, 1234 because some company made their old password insecure by forcing them to change it, make it too complicated, and have a trillion different login portals.

    @svampebob007@svampebob0073 жыл бұрын
  • Thank you for that great product advertising. But I'm missing one topic completely: PGP transfered keys to the YubiKey: a) Usage in general b) What if you loose the YubiKey with the transferred private PGP key part? Just use the key backup that you hopefully did before transferring it? c) How do you revoke already published PGP keys from an lost YubiKey on the corresponding (public) PGP key servers? I'm currently struggling a bit with that YubiKey 5 NFC variant to use it with my PGP in order to sign or encrypt my mails on desktop client or on android client using the NFC interface...

    @alpham8754@alpham87543 жыл бұрын
  • im now a fan of yubi keys looking to get one or two Great Video

    @italodelcol3241@italodelcol32412 жыл бұрын
  • Thanks Chris for this informative video, do you know if the use of yubikeys are supported for the firefox browser?

    @BeateThomsen@BeateThomsen2 жыл бұрын
  • great content as always! thanks

    @nightingalebird204@nightingalebird2042 жыл бұрын
  • Regarding Tile, they work via bluetooth not GPS, so they will only give their location if they are near your phone (or near someone else's phone with the tile app). It works well for if you can't find your keys in your house or to check they're in a bag, much less useful for tracking a stolen bike.

    @jonathanshaw6784@jonathanshaw67843 жыл бұрын
  • Thank you for this very good introduction to the topic. My question is: What about open source alternatives to the Yubikey, are they any good?

    @Hublium@Hublium Жыл бұрын
  • Awesome video dude.. Keep making more

    @NickAlways@NickAlways3 жыл бұрын
  • Great review, thank you

    @flymoracer@flymoracer3 жыл бұрын
KZhead