Hacker News new | ask | show | jobs
by andimm 2439 days ago
I know Yubkeys can be used as a second factor for apps but can you use them to unlock a phone aswell?
1 comments

Yubikeys can do FIDO along with storing a static complex password. I know android phones can lock with a password so it seems possible but it would be extremely clunky to have to plug in your key every time you unlock your phone.
Also sorta silly, because you are going to have to carry it with your phone anyway.
In the scenario "I forgot my phone and now it's gone" the Yubikey offers perfect security, because I'm unlikely to loose both my phone and my keyring with my YubiKey (that assessment might not hold for a woman with a handbag). In any targeted attack it's useless.
But if you need the FIDO key to use the phone you actually are likely to lose both at once, surely?
Only as likely as you are to lose your phone at the same time as your keys today, which as GP says depends on your habits / how you carry them.

It's not perfect, (and my Yubikey doesn't support it so I don't do it) but what is?

> Only as likely as you are to lose your phone at the same time as your keys today

This makes no sense and I struggle to even comprehend how somebody could come to this conclusion.

Before: I take my phone out, I unlock it, I look at something on the phone, then I get distracted, I leave it on a bar, a desk, somebody's refrigerator, wherever.

Now: I take my phone out. I need the FIDO key to unlock it, so I get that out too, I unlock the phone, I look at something on the phone, and then I get distracted and this time leave both the FIDO key and the phone in the same exact place, because of course I do I was using them both when I was distracted.

Can at least one of the people who seems so sure that somehow this wouldn't alter how often they lose the two items they now need together explain their thinking? Do you just... lose things randomly like maybe you have a gaping hole in your pocket and things fall out but you've never bothered to repair it? How are you losing things so that it somehow doesn't matter whether they're used together?