Do This Now! Yubikey + Google U2F Setup - EASY!

แชร์
ฝัง
  • เผยแพร่เมื่อ 25 ส.ค. 2024

ความคิดเห็น • 108

  • @eddielegs344
    @eddielegs344 ปีที่แล้ว +5

    Finally someone who explains and shows clearly.
    Many channels lot of fuss and not proper explanation. Thanks for that. Gtz

  • @Weaver0x00
    @Weaver0x00 ปีที่แล้ว +5

    you make some pretty niche content but its valuable to those who deliberately search for it, keep it up

  • @robdavy4468
    @robdavy4468 ปีที่แล้ว +1

    That flashback shot to 2020 was striking! Such a different visual look!

  • @drescherjm
    @drescherjm ปีที่แล้ว +1

    I purchased my Yubikey last week. The initial reaction was a lot of frustration (even as software engineer with 26 years of work experience) as many of my most important sites (financial ...) would not use it or prevented me from accessing my security settings from home (microsoft office 356 from work). I did get two of my important accounts setup and that is very helpful as I don't always have my smartphone within arms reach. I am watching these videos to learn about the features and to enable more accounts when possible. Since I have only 1 key at the moment I prefer to have an option for a second form of 2fa to an authenticator app in addition to the key.

    • @CrosstalkSolutions
      @CrosstalkSolutions  ปีที่แล้ว +1

      You can have an authenticator as a backup to a Yubikey! Check out my Yubikey Backup video...

    • @drescherjm
      @drescherjm ปีที่แล้ว

      @@CrosstalkSolutions Thanks. I will do so when I get time.

    • @drescherjm
      @drescherjm ปีที่แล้ว

      Once at the office I was able to setup my Yubikey with the more secure office 365. I have 2 different office 365 accounts from work because my employer is both a university and a large hospital system. I work for the university doing medical imaging research for the hospital system.

  • @bonareal7556
    @bonareal7556 ปีที่แล้ว +1

    Respect and reverence (in Russian uvazuha) to you for this informative video!

  • @Yves_Cools
    @Yves_Cools ปีที่แล้ว +2

    Excellent tutorial video, Chris !!! I would love to see some more to cover other online services (email and others) that can use these security keys. 🙂🙂🙂

  • @pachjo123
    @pachjo123 ปีที่แล้ว +2

    I did this last year because people keep trying to break into my Gmail account for some reason and my Microsoft account. This pretty much put a stop to it especially my Gmail because my account is an original beta account and is very old, I think people want my alias for Gmail.

  • @tomstechnews
    @tomstechnews ปีที่แล้ว

    Hey Chris! Great and useful video to increase security by Yubikeys. Got my pair yesterday! Will follow your steps! Thanks and please produce more interesting vids ! 👍💪

  • @MikeHarris1984
    @MikeHarris1984 ปีที่แล้ว +1

    Apple finally added NFC for Yubikey in 2019, and Android had it for years.... I was at Gartner IAM in Vegas in a meeting with yubico execs to bring them into my company as a security key provider when apple announced it. Everyone jumped up and celebrated over the news. Until then, Apple ONLY allowed NFC to be used with APPLE devices. I believe whole heartedly in FIDO and U2F and pushed to bring them into my company I work for as a Sr Lead Cyber Security Architect/Manager and was able to succeed. I use my Yubikey for all my accounts security and paired with LastPass where my Yubikey is the key to unlock my vault too where i have thousands of accounts stored and extremely secure passwords that I rotate every 90 days.... Not letting anyone in my world.

  • @markarca6360
    @markarca6360 ปีที่แล้ว +1

    I am set on using hardware keys (also removing mobile numbers in ALL of my online accounts) because the Philippine government (I am currently living in the Philippines) recently enacted mandatory registration of prepaid SIM cards.

  • @NicoBille
    @NicoBille ปีที่แล้ว +1

    Or better don't use google services and secure other services with it.
    ...ok, that makes no sense to write this on youtube ;-D
    Good advice and thanks for all the good videos. Watching since years, but I think i never wrote a comment.
    What I really appreciate is that you do follow ups for many things!

    • @BrewedIt
      @BrewedIt ปีที่แล้ว +1

      Exactly my point of my comment. Unique identifier on yubikey and giving that to G, No thanks. Other services and uses a maybe.

    • @NicoBille
      @NicoBille ปีที่แล้ว

      @@BrewedIt Yes and no. Securing your services is always a good idea. Degoogling a bit is also something good.
      I never thought if the yubikey could be used to track someone, that is a thing I need to search for. If yes: it's to decide how valuable your googleaccount is. Enough to secure it otherwise or enough to buy more yubikeys or similar.
      And for degoogling: I think here it is about not to try completely go away, but in steps. E.g. there is not only gmail out there. Other search enginges could be useful, too. And a bit more competition could make some googleservices more userfriendly.
      But that idea with tracking because of the yubikey is interesting. I really need to research it.
      (Or wait a few weeks and Chris takes on this topic? ;-) ).
      However, thank you very much for this point I'm gonna to look after.
      In fact I just received yubikeys two days ago but haven't set them up.

  • @user-wl9zx7oe3x
    @user-wl9zx7oe3x 9 หลายเดือนก่อน +1

    ممكن الاستفادة منه

  • @dude7189
    @dude7189 ปีที่แล้ว +1

    I'm trying to find out if the "flipper zero" can emulate a yubikey (as i heard the flipper zero can copy and emulate any thing that uses wifi bluetooth or nfc) and let someone use the flipper zero to access your yubikey locked account

  • @1Samuel1524
    @1Samuel1524 4 หลายเดือนก่อน

    2:20 it defaults to Google authenticator and has no other options listed.

  • @dudeh9702
    @dudeh9702 ปีที่แล้ว +2

    Curious how you use three different Yubikeys. I understand the best practice of primary and backup, but how do you use three in your daily life?
    I've put off moving from TOTP 2FA to U2F forever; thanks for the video to get me to finally order them.

    • @giggadan
      @giggadan ปีที่แล้ว +1

      Most people will only ever need 2 but for Chris specifically he’s got his company so it’s a bit different. It might be 1 for him, 1 for the second in command or the office, and 1 as a backup in a secure place. He’s talked about keeping 1 secure in a safe or bank before. Also it could be more than 3 as maybe each employee that needs access to the account gets one.

  • @LionRoars918
    @LionRoars918 ปีที่แล้ว +1

    The only problem is with the Google id/pwd you can disable 2FA. It is a huge vulnerability. They should require the key to be touched before allowing it to be disabled.

    • @vegasvato55
      @vegasvato55 ปีที่แล้ว

      I am finding a lot of good information on how to use a yubikey once it has been properly set up and activated, But i am not finding a lot of useful information on how to actually set one up and activate it... Any Suggestions???

  • @Gio-zi5lw
    @Gio-zi5lw 14 วันที่ผ่านมา

    I'm not sure if I did it right. For some reason, can only asked for my key one time. Unless I'm logging in into a new computer. Is that how it's supposed to be?

  • @Gio-zi5lw
    @Gio-zi5lw 14 วันที่ผ่านมา

    It asked me to create a pin? Also whenever I sign in for Google it's not asking for my yubico.

  • @beto8493
    @beto8493 หลายเดือนก่อน

    My Google account has an existing Yubikey registered and now I want to add a second key, but it seems Google changed the settings now it says "Passkeys and security keys" and it shows the existing security key but only shows the option to create 'Passkeys' not to add an additional security key. Is it still possible add security keys at Google?

  • @Morcego538
    @Morcego538 8 หลายเดือนก่อน

    Can you show us this using the flipper? The flipper does the nfc authentication on the smartphone?

  • @joellemorris5684
    @joellemorris5684 5 หลายเดือนก่อน

    thanks a lot for this great video!!
    But what about in the context of an office, I have multiple persons (let's say 4 in this example) wanting to sign in to a Google account from their office devices (6 laptops, 2 desktops, 1 tablet, 8 phones), how should I buy 4 Yubikeys and then register them in Google?

  • @wildflower20102
    @wildflower20102 4 หลายเดือนก่อน

    I don't seem to have option to add other YubiKey. I don't have "+ Add security key" as a option under the key I have already set up. Please help

  • @10_Roads
    @10_Roads 21 วันที่ผ่านมา

    Why do google need to see the make and model of the key? Is there any way to bypass this on Windows? My friend on Linux could just select "no" and still get the key working.

  • @edEdrbp556
    @edEdrbp556 ปีที่แล้ว +1

    Thanks yu ❤️

  • @IndianaDiy
    @IndianaDiy ปีที่แล้ว

    YubiKeys are awesome! I have several, I’m considering buying the YubiKeys FIPS keys in future. I have been using Authy 2FA and YubiKeys.

  • @Melker63
    @Melker63 3 หลายเดือนก่อน

    I currently use Google Authenticator. Is it possible to keep that until Yubikey is installed and up & running. And THEN disable and delete Goggle authenticator?

  • @WayneRigley
    @WayneRigley ปีที่แล้ว +1

    so should we have 2 keys just in case or will one key and backup codes work fine ?

  • @Przyziemni
    @Przyziemni ปีที่แล้ว

    Should we switch off 2 step verification after adding Yubikey ? And leave only that key? thx - maybe i miss that my English is like it is... thank you great content

  • @loliwaifu
    @loliwaifu ปีที่แล้ว

    Thanks!

  • @briantodd6903
    @briantodd6903 6 หลายเดือนก่อน

    Is that the same camo key that you used on apple iPhone maybe better question can you use the same key on different devices ty

  • @dani-uf1eo
    @dani-uf1eo ปีที่แล้ว

    Ever since "the video" I look at the background very carefully to see if you post another qr code lol.

  • @VitoAD
    @VitoAD ปีที่แล้ว

    Hey Chris thanks for another great Video. I did see this when it came out but just now set up my YubiKeys on my Google account. I did set up my YubiKey on Google using OTP. Now that I set up the physical key can I remove the OTP or leave it setup?

  • @ProxyPacIT
    @ProxyPacIT ปีที่แล้ว

    Should always uncheck remember this device, in using u2f the last 2 years

  • @snana9665
    @snana9665 ปีที่แล้ว

    I have added 2, but it only shows 1 key in the list. When I try to re-add the other, it says “sorry this device has already been registered.” I wonder why they don’t both show up?

  • @mmnairkochi
    @mmnairkochi 5 หลายเดือนก่อน

    Do you have to setup Yubikey separately in Windows, iPad and Android phone as I use Gmail on all three platforms?

  • @outbackeddie
    @outbackeddie 6 หลายเดือนก่อน

    If I set up some accounts on my desktop computer with a Yubikey USB-A device won't I be locked out of accessing those accounts on my iPad? If so, is it possible to buy a Yubikey with a lightning connector and add it to the existing Yubikey 2FA methods? I'm a little confused on how this will work since I will be locked out of accessing the accounts on the iPad.

  • @3linkgaming
    @3linkgaming ปีที่แล้ว

    I have doubt for single key how many accounts can be used

  • @davidjohnson2782
    @davidjohnson2782 ปีที่แล้ว

    What do you think of v6 of the Yubico Authenticator Desktop App?... on the Mac, it no longer lives in the menubar and doesn't automatically copy the OTP after touching the key.

  • @CHUMLAR
    @CHUMLAR ปีที่แล้ว

    Should I also setup the key for my passkey vs the 2step key?

  • @Aepek
    @Aepek ปีที่แล้ว

    8:29 ¹ @crosstalk solutions this b/c you didn’t “unselect” don’t ask again for this device on your phone or PC; assuming that means won’t need to use the “Key” again?
    If that’s the case, the security is back to where it was or no; and also, if do forget to unselect that box…..how to you go into settings and clear out “saved devices”?
    Thx for this how to vid, dry useful and like that the key is also nfc for basically anything as laptops now support nfc; which also begs the question….is nfc secure enough to be using?
    Cheers✌🏻
    ¹ edited cuz forgot the time stamp, OPPSY

  • @abyb2135
    @abyb2135 11 หลายเดือนก่อน

    Can the finger print be used/transferred/leaked as a means to identify you and connect you as the owner to your mail account online or does the finger print information stay within the hardware mechanism of the yubico key itself?

  • @vegasvato55
    @vegasvato55 ปีที่แล้ว

    I am finding a lot of good information on how to use a yubikey once it has been properly set up and activated, But i am not finding a lot of useful information on how to actually set one up and activate it... Any Suggestions???

  • @shotbyarian
    @shotbyarian 7 หลายเดือนก่อน

    should i deactivate the possibility to login by using my phone and granting access? i login with email + pw and then there comes a popup on my phone which i can press yes and then i am logged in even though i have a yubikey

  • @new-knowledge8040
    @new-knowledge8040 11 หลายเดือนก่อน

    3:24 It is at that point that all fails. After inserting the key, it asks me to enter my security key PIN ??? What to do ?

  • @frankmalcolm1321
    @frankmalcolm1321 ปีที่แล้ว +1

    Chris, I get U2F using a Yubikey is better than OTP. But can the NFC data from the Yubikey be acquired and used for access, by using something like the Flipper Zero or another device?

    • @CrosstalkSolutions
      @CrosstalkSolutions  ปีที่แล้ว +2

      No it can not - the Flipper Zero can't read the cryptographic key that comes along with stronger NFC cards like the Yubikey.

  • @Michi_84
    @Michi_84 ปีที่แล้ว +1

    Im using Keepass on Win 10. And Keepass2Android on my Samsung.
    Database is on a Server...
    Can i use the same Database from Win10 and my Samsung with a Yubikey?
    Not ordered 1 or 2 yet.

    • @CrosstalkSolutions
      @CrosstalkSolutions  ปีที่แล้ว +2

      The Yubikey is not a password manager. It can however be used to secure your password managers.

  • @richstilke1227
    @richstilke1227 ปีที่แล้ว

    I've had 2FA on for the last 3 months, and it's never asked for my Yubikey.

  • @jackwong64
    @jackwong64 ปีที่แล้ว

    Why yubikey when we have smartphone?

  • @turbo2ltr
    @turbo2ltr ปีที่แล้ว

    I use OTP on yubikey with backup on a fidesmo card using an authenticator app.. So unless they can mind control me to run the app and read the card, they ain't phishing anything.

  • @alaaji2
    @alaaji2 ปีที่แล้ว

    Why did you leave the "Don't ask again on this device?" box checked on both of your devices? Doesn't that defeat the purpose of having all that security?

    • @GiveMeAnOKUsername
      @GiveMeAnOKUsername 11 หลายเดือนก่อน

      I think that once Google is "installed", one trusts one's device (e.g. face Id) to control access.

  • @vincentharn
    @vincentharn ปีที่แล้ว

    Is there a way to see what U2F keys are on a Yubikey? I have multiple Yubikeys like you and can't remember if all my accounts are registered to all the keys. Could not find anything online.

  • @maksymhromyk1375
    @maksymhromyk1375 11 หลายเดือนก่อน

    that's not a purpose of yubikey. The power comes with passkeys and unfortunately, yubikey doesn't work with multi google accounts.

  • @summerbee80
    @summerbee80 ปีที่แล้ว

    hi chris, Im trying to setup all the tp link hardware you showed in your previous videos but the DHCP authentication does not accept my ISP DHCP 60,61 request. The archer VR2100 can but this means having to purchase another router just to have the tp ER605 connect. I know there is no way around this so what method would you use?
    Ive been told i can change the subnet but by doing this i will get double NAT and some people still do this and no issues with their connectivity. I need your help!

    • @vegasvato55
      @vegasvato55 ปีที่แล้ว

      I am finding a lot of good information on how to use a yubikey once it has been properly set up and activated, But i am not finding a lot of useful information on how to actually set one up and activate it... Any Suggestions???

  • @belowasmelashgebremariam
    @belowasmelashgebremariam ปีที่แล้ว

    Keney ke selam do asme

  • @HoldenRiot
    @HoldenRiot ปีที่แล้ว

    Is it recommended that you add both the two keys to the account or is there a way to copy the first key seed (5NFC) and paste it into the second key (5CI) using the Yubikey software?

    • @LionRoars918
      @LionRoars918 ปีที่แล้ว +1

      It can be done but it's difficult.

    • @HoldenRiot
      @HoldenRiot ปีที่แล้ว

      @@LionRoars918 thanks for the reply! Sounds easier to just add them separately then so they are more isolated and that way you can simply remove them individually if one was ever lost.

    • @LionRoars918
      @LionRoars918 ปีที่แล้ว

      @@HoldenRiot I had to use DOS software as the Yubikey windows software would not do it. My keys are identical except for the SN.

    • @HoldenRiot
      @HoldenRiot ปีที่แล้ว

      @@LionRoars918 oh wow. Interesting! I’m surprised their software doesn’t allow for that yet. Good to know though, thanks!

  • @heymomarockme
    @heymomarockme ปีที่แล้ว

    I show three yubikeys registered on my google account but I’m not prompted at login. Maybe I selected ‘trust this device’ or maybe have a SMS number listed too? Shouldn’t it ask on reboot, or when I open a google browser page? Or maybe I had google remember the password, and that bypasses U2F? Any pro tip to engage U2F? What are the instances where U2F will not engage? Also will it work with the iOS gmail app on my iPad?

    • @LionRoars918
      @LionRoars918 ปีที่แล้ว

      If someone else tries to access your account they will be prompted, that is the important part.

    • @Gio-zi5lw
      @Gio-zi5lw 14 วันที่ผ่านมา

      I'm also having the same issue. Is it supposed to prompt up every time you log in or only to a new device that's not register in your Google account?

  • @Moonraker11
    @Moonraker11 ปีที่แล้ว +1

    What's that flashing thing in the background?

    • @CrosstalkSolutions
      @CrosstalkSolutions  ปีที่แล้ว +1

      JBL Pulse 3 bluetooth speaker. I have the Pulse 4 as well - great speakers!

  • @coldhardfacts1874
    @coldhardfacts1874 ปีที่แล้ว

    Does the camo make it invisible? :]

  • @BrewedIt
    @BrewedIt ปีที่แล้ว

    Good video. However the serial or unique ID of your yubikey is something in the dark corner as to speak, that can be attributed to you. For those that like privacy it's another discussion all together.

  • @18199
    @18199 ปีที่แล้ว

    Interesting that your painting on the wall is to UK colour code and not to the US. Or B instead of A depending on how you interpret it. Looks cool either way.

  • @SmedleyButler1
    @SmedleyButler1 ปีที่แล้ว

    Is any info transmitted "home"? Anyone watch the packets? Sure , "checking for updates" every day is really "necessary", like Logitech garbage. Anyone not so gullible really checked?

  • @subaedahsoc
    @subaedahsoc ปีที่แล้ว

    Semoga hak saya bsh kembali.

  • @chrisridd9423
    @chrisridd9423 ปีที่แล้ว +1

    Yubikeys are good, but if you've got a Mac with Touch ID on its keyboard then that's actually a very good alternative. Possibly better, as it checks your fingerprint whereas Yubikeys will work with anyone's finger. Either way, Mac users have built-in support for U2F for 2FA.

    • @BrewedIt
      @BrewedIt ปีที่แล้ว +1

      There's the newer yubi keys which support biometric fingerprint, not just touch the sensor area. Think its v5 or something.

    • @chrisridd9423
      @chrisridd9423 ปีที่แล้ว +1

      @@BrewedIt you’re right, the yubikey 5 bio. There’s no NFC version of them yet though. Anyway my point was that Touch ID is a very good substitute.

    • @GiveMeAnOKUsername
      @GiveMeAnOKUsername 11 หลายเดือนก่อน

      But Touch Id doesn't stop a random person from logging in to your Gmail if they have your password and have hacked your phone - it only controls access to your device.

    • @chrisridd9423
      @chrisridd9423 11 หลายเดือนก่อน

      @@GiveMeAnOKUsername no, you can store certain things (eg WebAuthn/passkeys) in the iPhone's Secure Enclave and these can only be accessed using Touch ID. If you know of a way to breach the Secure Enclave then I'm sure Apple would love to talk to you and pay you a huge bug bounty.

  • @mikebroom1866
    @mikebroom1866 ปีที่แล้ว +1

    Until you need to log in to a system that blocks USB.

    • @CrosstalkSolutions
      @CrosstalkSolutions  ปีที่แล้ว +3

      This is pretty unrealistic. An admin typically wouldn't both require U2F and also block USB. That would be dumb.
      And if you're trying to log into a U2F protected account from a kiosk computer or any device that doesn't have or blocks USB - then yes...you're out of luck. But again - unrealistic scenario.

    • @raiden72
      @raiden72 ปีที่แล้ว

      @@CrosstalkSolutions would using USB yubikey then inherently reduce the security of the system by allowing end users to insert random USB sticks onto a corporate network connected device?
      Is there a tradeoff here?

    • @chrisridd9423
      @chrisridd9423 ปีที่แล้ว

      @@CrosstalkSolutions we have admins who are looking to block USB mass storage devices. It is not clear if it'll block U2F keys too. Sounds like it could be a bit of an own goal :-)

    • @zachrose
      @zachrose ปีที่แล้ว

      It's also a problem if you are remoted into a system. For instance I RDP into my VM everyday for work and if I launch a browser on that machine and try to log in to an account I wouldn't be able to use my Yubikey. I've kept OTP on my Google account for that reason. I don't really see an easy way around it.

    • @beepboopbeepboop190
      @beepboopbeepboop190 ปีที่แล้ว

      @@zachrose The yubikey works over vpn/rdp in a browser inside the rdp session.

  • @fordonmekochgalenskaper5665
    @fordonmekochgalenskaper5665 ปีที่แล้ว

    Just hate how the yubikey is built, have broke 5 in less than a year, I need to have then with me whole time

    • @CrosstalkSolutions
      @CrosstalkSolutions  ปีที่แล้ว +1

      What do you have a combine in your pocket? Lol…I’ve had one on my keychain in my pocket for 3 years and it’s fine.

    • @fordonmekochgalenskaper5665
      @fordonmekochgalenskaper5665 ปีที่แล้ว +1

      @@CrosstalkSolutions I have tools and keys and other crap in my pockets so it is an hard environment there

  • @a.g8517
    @a.g8517 ปีที่แล้ว +1

    such a joke to use Gmail as a private email server🤣

  • @rgbug1121
    @rgbug1121 ปีที่แล้ว +1

    It's a shame Protonmail still doesn't support this.