Author

Topic: Yubikey cross-service security? (Read 843 times)

newbie
Activity: 19
Merit: 0
April 21, 2013, 07:34:37 AM
#2
They are correct in their assertion, presuming an untrust worthy service provider. If I were them I would not allow my security to rely on the skill or goodwill of others.

It would be best practice. Especially if you are effectively only using it as a password i.e. single factor authentication.

The danger is that a site you are logging in to will reuse your login details to access another site you might also use. Effectively your classic man in the middle attack.
hero member
Activity: 905
Merit: 1033
BTC: the beginning of stake-based public resources
April 18, 2013, 09:41:38 AM
#1
Some websites - e.g. MTGOX - only issues Yubikeys from themselves which are locked to one account only. They state this is done for security purposes as if a Yubikey is used on multiple accounts with different providers one of the providers can use your code to log into another account with another provider.

I am therefore wondering if it is best practice to have one key per provider or if it is ok to use one Yubikey with multiple different accounts and providers.

Can anyone clarify why this is?
Jump to: