Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not saying the 4C doesn't do U2F. It's the same as the 4. I'm saying that if all you want to do is log into web services, you probably don't want the Y4.


more features can even be harmful as in default OTP mode of those devices: https://hackernoon.com/avoid-leaking-your-identity-with-yubi...


Its a good thing to think about, but I don't see it as a huge problem. I had a Yubikey Nano plugged into my laptop almost constantly and I do trigger the OTP sometimes, but using that as an attack vector is pretty hard, specially for all the sticks that are not always plugged in.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: