• Welcome to Peterborough Linux User Group (Canada) Forum.
 

New two-factor security key coming out; made by Google

Started by fox, July 27, 2018, 10:40:30 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

fox

Looks to be cheaper than the current versions of Yubikey, and will be available in usb and bluetooth versions. Read about it here.
Ubuntu 23.10 on 2019 5k iMac
Ubuntu 22.04 on Dell XPS 13

Jason

Interesting. Thanks for sharing. Good article for explaining why everybody should be using 2FA. I'm not sure about a Bluetooth model. Bluetooth can be pretty flaky and goes too great a distance for being secure in my opinion. But more competition can't hurt.

Btw, anybody can use 2FA even without a hardware key (and you should). You just download the Google Authenticator app to your phone/tablet which, despite it's name, can be used for lots of different services. But a 2FA hardware device makes it so much easier. No numbers to have to type in. Just plug it in or if it's already plugged in, just touch it. As Google has discovered, it pretty much wipes out phishing vectors. With Linux, you can even use with encrypted drives.
* Zorin OS 17.1 Core and Windows 11 Pro on a Dell Precision 3630 Tower with an
i5-8600 3.1 GHz 6-core processor, dual 22" displays, 16 GB of RAM, 512 GB Nvme and a Geforce 1060 6 GB card
* Motorola Edge (2022) phone with Android 13

fox

Quote from: Jason Wallwork on July 27, 2018, 05:27:44 PM
....
Btw, anybody can use 2FA even without a hardware key (and you should). You just download the Google Authenticator app to your phone/tablet which, despite it's name, can be used for lots of different services. ....
I found a short video here which explains how it works. As I understand it, you don´t have to keep entering the verification code if you have the Google Authenticator app. But what if you want to sign in to a Google service on your computer. Do you have to have to authenticate there each time?
Ubuntu 23.10 on 2019 5k iMac
Ubuntu 22.04 on Dell XPS 13

Jason

Quote from: fox on July 27, 2018, 07:26:54 PM
As I understand it, you don´t have to keep entering the verification code if you have the Google Authenticator app.

You mean you don't have to keep entering it when you use various Google apps on your phone? That's correct.

QuoteBut what if you want to sign in to a Google service on your computer. Do you have to have to authenticate there each time?

Yes, you do have to enter the verification code each time because it's only good for a particular time (a maximum of a minute). In the Authenticator app, it shows each passcode and a like a pie-chart circle shrinking in size as it counts down. Every minute it's a new passcode, for each and every service registered with Google Authenticator.

Now if you don't want to enter it every single time you login, for example, on a trusted computer (that's not shared), you just tick the box that says 'Don't ask for codes again on this computer'. Thereafter it looks as if you don't have 2FA though you still get the protection that anybody trying to hack your account on google won't be able to get into it even with your password. They need that cookie saved on your drive. I do that on my home computer. I don't do it on my laptop because if I lose my laptop and somebody brute forces my password, I'm SOL. This is especially important for LastPass which stores all my passwords.

Hope that helps. Be happy to show you sometime how it works.


* Zorin OS 17.1 Core and Windows 11 Pro on a Dell Precision 3630 Tower with an
i5-8600 3.1 GHz 6-core processor, dual 22" displays, 16 GB of RAM, 512 GB Nvme and a Geforce 1060 6 GB card
* Motorola Edge (2022) phone with Android 13

dougal


fox

Thanks for reporting this, dougal. I was hoping that the price would be lower, but Google's version connects in just about every way possible, so would be useful for all kinds of devices. I'm pretty sure that they will release in Canada very soon.
Ubuntu 23.10 on 2019 5k iMac
Ubuntu 22.04 on Dell XPS 13

Jason

Cool. Not sure about them including Bluetooth, though. From a security standpoint, I'm not sure about Bluetooth. I've worn my Bluetooth headphones taking garbage out and I got almost to the curb before it flaked out.

Anyway, I noticed on the blog that you're actually buying two keys for that price, a Bluetooth one and a USB-A one. It also comes with adapters for micro USB and USB-C.
* Zorin OS 17.1 Core and Windows 11 Pro on a Dell Precision 3630 Tower with an
i5-8600 3.1 GHz 6-core processor, dual 22" displays, 16 GB of RAM, 512 GB Nvme and a Geforce 1060 6 GB card
* Motorola Edge (2022) phone with Android 13

fox

One of the advantages of having a physical security key for two-factor authentication is that it works without having to remember yet another password. However, once set up, what happens if you lose the device itself? Is there some way to still access secure files?
Ubuntu 23.10 on 2019 5k iMac
Ubuntu 22.04 on Dell XPS 13

Jason

#8
Quote from: fox on September 22, 2018, 07:35:27 AM
One of the advantages of having a physical security key for two-factor authentication is that it works without having to remember yet another password. However, once set up, what happens if you lose the device itself? Is there some way to still access secure files?


That question was asked and answered elsewhere in the forums.

And I want to be clear, you still use a password alongside with two-factor authentication. What I mean is that, for example, when you login to Gmail, you will enter your username and password (as you did before you added 2FA) and then insert your security key. I don't want people to think that it does away with ever remembering passwords. But if you're smart and use a password manager like Bill and I do, you only have to remember one password and the manager provides the rest.

Update: I provided the link I was trying to find that answers the question of how to prepare in case you lose your security key.
* Zorin OS 17.1 Core and Windows 11 Pro on a Dell Precision 3630 Tower with an
i5-8600 3.1 GHz 6-core processor, dual 22" displays, 16 GB of RAM, 512 GB Nvme and a Geforce 1060 6 GB card
* Motorola Edge (2022) phone with Android 13