Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Saturday, September 10, 2022

Ledger Nano S Plus - Setup and initial thoughts

I recently obtained a Ledger Nano S Plus.  It was custom branded for Tribe X, one of the NFT projects that I am participating in.  The packaging was very nice and simple, it included the device itself, paperwork, a USB A to C cable and a keychain loop.





Setup - Initial setup

I went to www.ledger.com/start to get the process going.  For my first test/setup, I was just going to create a new wallet like a normal new user would.  The process went pretty smooth, and I was up and running on my Ledger pretty quickly.

A few recommendations:
  • Make sure you pay attention to the setup screen information, it is useful especially for a new user.
  • Make sure you write down your recovery phrase on a paper, do not store it in a file on your computer - that would defeat the entire purpose of an offline/cold wallet.

Setup - Recover prior software wallet

First, let me say that my next test was just a test and you should NOT do this for actual long term use of your device.  I already had a prior software wallet, so I decided to recover that wallet onto my Ledger.  This is a HORRIBLE idea from a security perspective since it defeats the purpose of a hardware wallet but for testing it was fine.  As expected all my old stuff showed up fine, so I plan to use this setup for testing to see how it impacts things for me.  Most of the services I deal with support WalletConnect, which is supported by Ledger Live (the desktop/mobile app that interfaces with the Ledger device).  I had one site that doesn’t support WalletConnect, but MetaMask did work.  The only thing I don’t like is you can’t get to the point of using Ledger in MetaMask if you don’t have a MetaMask account setup.  However for most users, they likely have a MM account so this shouldn’t be a problem.

FIDO U2F Support

While the Ledger is mainly focused on crypto, it does have a feature that users should look into a security capability for their online accounts.  The Ledger can support FIDO U2F (two-factor authentication).  You can read up on Ledger’s info on this feature here ( https://www.ledger.com/fido-u2f/ ).  If you read my blog, you know that I have tested Yubikey hardware tokens.  For the Ledger implementation, two things stood out as interesting:

  • The Ledger is PIN protected, so someone can’t use your hardware token if they don’t know your PIN.
  • You can restore your recovery phrase on another Ledger wallet and get access to your FIDO U2F again.
From a security standpoint the ability to recover your key onto another device means that if someone gets your crypto private key, they can restore onto a Ledger and also get access to your FIDO U2F so depending on how paranoid you are that might be a bad thing.  However it also means that, as long as you know your crypt recovery info you can always restore your FIDO U2F access on a Ledger device.

Thoughts so far

The increased security adds some complexity to the process.  If you are used to just having a software wallet like MetaMask, you now have to remember to keep your Ledger nearby.  However the increased security, keeping your key on a hardware device and not in your software, is worth it for anyone in the crypto/NFT world in my opinion.  Remember, this helps to secure your private key but you still have to be careful with the sites you interact with.  Ideally you keep your hardware wallet for “trusted” sites and never use it for minting and maybe do your minting type activities on a software wallet to keep some separation.  If you already have a software wallet, just move your valuable NFTs to your Ledger and keep using the software wallet for minting.

Saturday, September 11, 2021

Yubikey - Using Yubico Authenticator

This post is focused on setting up your accounts to use Yubico Authenticator on a Yubikey.  If you are looking to add your Yubikey as a hardware token / security key, check out my other post ( https://bigboystoys13.blogspot.com/2021/09/yubikey-adding-security-key-to-your.html ).  If you don't have a Yubikey yet, you might want to check out this post instead ( https://bigboystoys13.blogspot.com/2021/09/yubikeys-quick-review.html ).

The Yubico Authenticator works similar to many other Authenticator apps like Google Authenticator, Microsoft Authenticator and many others offer.  A main difference with Yubico's option is that the information is stored on your Yubikey, not on your computer or other device.  Of course remember this also means if you lose your Yubikey you lose that authentication option so always make sure you have alternate / backup options.

Before you start setting up accounts

- Make a list of the accounts you want to setup.  It helps to keep track in case you lose your Yubikey or need to change your setup later.
- If you have more than one hardware token, have them all ready.
- Give each key a unique nickname, in case you need to remove/disable it later.  If the devices have different colors or are different models that makes it easy.  If you have two of the same device, maybe use part of the serial # or use stickers to tell them apart.  The nickname can be based on where you store it (Safe, Keychain) whatever makes sense to you even a year or two later.
- Make sure you setup the Yubico Authenticator on the device you plan to use for setting up your accounts.  I would recommend you consider adding a password (on Android you can go to the 3 dots and choose "Change password" to require a password to access the codes).

TIP: If you are setting up two Yubikeys, you could do the setup of one on one device (computer for example) and the other on another device (your phone for example).  It will keep you from having to swap keys on a single device.

Steps to setup Yubico Authenticator

1) Go into your account settings and then security settings.  Here are some sample steps for various sites:

PayPal: Settings > Security > 2-step verification
Amazon: Account > Login & Security > Two-Step Verification (2SV) Settings

If you can't find the option in your settings area search the support/help area of your page or contact support for the site.

2) Find the option to add an authenticator app, normally it will show a QR code that you can scan.  Once you scan the QR code, you should get a code that changes every minute or so in your Authenticator app.  If you are using two devices at the same time you can visually compare the generated codes to make sure they are the same otherwise, once you are done setting everything up it would be good to test each Yubikey that you configured.  I did notice that sometimes I had to swipe down in the app to get the code to refresh.

3) You might want to consider disabling the SME/text message option, go check out my other post ( https://bigboystoys13.blogspot.com/2021/09/yubikey-adding-security-key-to-your.html ) near the end section 4 explains a little more about this.

Useful Yubico Links:

Yubikey - Adding security key to your account

This post is focused on adding your Yubikey as a hardware token / security key to your account.  It does not cover setting up other options.  If you are looking to setup Yubio Authenticator, check out my other post ( https://bigboystoys13.blogspot.com/2021/09/yubikey-using-yubico-authenticator.html ).  If you don't have a Yubikey yet, you might want to check out this post instead ( https://bigboystoys13.blogspot.com/2021/09/yubikeys-quick-review.html ).

Before you start setting up accounts:

- Make a list of the accounts you want to setup multi-factor authentication (MFA) on.  It helps to keep track in case you lose your Yubikey or need to add a backup.
- If you have more than one hardware token, have them all ready.
- Give each key a unique nickname, in case you need to remove/disable it later.  If the devices have different colors or are different models that makes it easy.  If you have two of the same device, maybe use part of the serial # or use stickers to tell them apart.  The nickname can be based on where you store it (Safe, Keychain) whatever makes sense to you even a year or two later.

Steps to setup the hardware tokens.  These basic steps work with many services ( Google, Microsoft, Facebook, Twitter, and Yahoo for example ).

1) Go into your account settings and then security settings.  Here are some sample steps for various sites:

- Google: From Gmail, click your icon in the top right and choose "Manage your Google Account".  In there click "Security" and go to "2-Step Verification".
- Microsoft. From www.microsoft.com, click your icon in the top right and then choose "My Microsoft Account".  Then click "Security" and "additional security options".
- Facebook: Go to the "Settings & Privacy" menu in the top right, then "Settings".  Next go to "Security and Login" and look for the "Two-Factor Authentication" section.

If you can't find the option search the support/help area of your page or contact support for the site.

2) Find the option to add a security key / add a new way to sign in and add your token.  Do this with each token you have.

3) Look at other backup options, especially if you only have one key.  Examples:

- Authenticator app: There are many options - Google and Microsoft have an option, so does Yubico itself and many other options are out there.  This is a good option, but remember if you lose your phone you lose the app with it.  If you plan to keep your key with you that is a problem (since you could lose both items at the same time), but if you plan to keep the token in a safe using the Authenticator app on your phone might be ok.  You could setup Yubico Authenticator on your Yubikey, but the whole point is that you want a backup if you lose Yubikey.  Yubico Authenticator on a token isn't a backup if it is on the same exact token.

- Backup codes: One time use codes that you can put somewhere, maybe print them and put them in a safe.  However don't put it in the same safe you have a spare Yubikey.

4) This might be a good time to disable SMS/text messages/voice calls as an option.  If you Google search "is SMS MFA secure" you will see many articles addressing issues with SMS, and since you have a hardware token as better option might as well get rid of the weaker link.  If you felt SMS was good enough, you probably wouldn't be using or researching a hardware token.

Tuesday, September 7, 2021

Yubikey - Quick Review

This is just going to be a (sort of) quick, high level, review of a two Yubico products and some other hopefully helpful tips.  I sort of laid things out as if someone was asking me questions.

What is a Yubikey?

For now I am going to avoid explaining terms like dual-factor authentication, or multi-factor authentication because if you are reading this post you are probably somewhat familiar and interested.  The Yubikey is a hardware token you can use for authentication.  Yubico itself has a "Why Yubico" page ( https://www.yubico.com/why-yubico/for-individuals/ ) with some good high level information about their products.  There are other products out there, I personally decided to go with Yubikey devices but do your own research.

Do I really need one?

Simply put, a hardware token can help protect your online accounts against compromise.  How bad would it be if your online accounts were taken over - not just that someone logged into your account, but they took control of it or erased everything?  Don't forget your e-mail account is often used to gain access to other accounts, so one compromised e-mail account could lead to an even larger impact.  Don't focus on the cost of the device, focus on the impacts you are avoiding.

Which one should I get?

With Yubico, I mainly looked at two options - Security Key NFC and Yubikey 5 series.  This my quick summary of the two options:

1) The Security Key NFC just has one option, that includes NFC and USB-A.  It supports common protocols like U2F and FIDO2, and works with many common providers like Google, Microsoft and Facebook.  Chances are you use at least one of those services.  The device is water and crush resistant, and does not require batteries.

2) The Yubikey 5 Series adds many other options above what the Security Key NFC provides.  Here are a few examples:
  • In addition to FIDO2 and U2F, these also support additional protocols like Smart card, OTP and OpenPGP 3
  • Multiple interface options ( USB-A, USB-C, NFC and Lightning ) and device styles
  • IP68 rated: dust tight and water submersible
Yubico has a quiz ( https://www.yubico.com/quiz/ ) that walks you through the process of picking the best option, and you can also check the catalog of sites that work with YubiKey ( https://www.yubico.com/works-with-yubikey/catalog/ ) to see if your service is supported.  I am not sure the quiz would actually even suggest the Security Key NFC - even when I picked simple options it didn't come up.  This page ( https://www.yubico.com/store/compare/ ) has a good comparison of the various products.

Do I really need a spare?

The quiz does ask if you want to get a spare device.  Imagine if you had a safe with 1 set of keys.  If you lost the key there would be no way to get into the safe.  A second hardware token isn't exactly a crazy idea, but in many cases you can also use other methods as a second authentication option so it isn't required.  No matter what, make sure your plans account for the fact your hardware token could be lost or damaged.  Some accounts let you print "one time use" codes, or provide other authentication options you can consider.

If cost is a factor, the Security Key NFC by Yubico is going to get you into this at a cheaper cost ( around $25 ).  However the Yubikey 5 series has more connector options and supported protocols, and is probably the better option for a tech savvy user that might want to try out some of the additional features.

What did you get and why?

Personally I ended up getting the Security Key NFC as my first device to get my hands on a hardware token, at some point you have to stop reading about it and just go for it.  For the simple use case of tying my accounts to a hardware token, the Security Key NFC did the job but the geek in me wanted to try out the 5 Series since it has extra features.

Yubico Authenticator is one of the features that works on the 5 series but doesn't work on the Security Key NFC.  I tested it out with a few accounts, just to see how it works.  If you already use apps like Microsoft or Google's Authenticator app on Android, then the Yubico app will be very familiar.  I did notice that the Android app does not seem to work on a Chromebook via USB-C, at least when I tested it.  The big difference between Yubico's app and other apps I have seen is that the information is stored on your Yubico token making it easy to move between devices, but I believe there is a limit on the number of accounts.  This page ( https://support.yubico.com/hc/en-us/articles/4404456942738-FAQ#what-is-the-yubikey-s-account-limit- ) you can find information about various limits.

As I mentioned earlier, the Yubikey 5 series has multiple connectors and form factors.  I went with Yubikey 5C with USB-C for future proofing since more devices use USB-C, but I also purchased USB-C to USB-A adapter from Syntech which so far has worked fine on a Windows laptop that only has USB-A ports.  For now I plan to keep my Security Key NFC as the "backup" device, and the Yubikey 5C as one I use to test out some of the new features.

I got one, now what?

If you decide to get a Yubikey, check out these other posts of mine that might help with some tips on setting it up:



Useful Yubico Links:
Quiz to see which device is best for you - https://www.yubico.com/quiz/
Catalog of services that work with Yubikey - https://www.yubico.com/works-with-yubikey/catalog/?sort=popular