I'm glad you mentioned they are separate entities, and aren't linked to each other. The backup key idea can confuse people. Really, there is no "backup key" and "primary key". They are just 2 keys that both can unlock the account.
@miguelb7789 ай бұрын
I agree, back up and primary creates confusion
@cipher8936 ай бұрын
The same way you have spare house keys.
@0nceuponatime486 Жыл бұрын
Just wanted to say thank you for making this. I was always annoyed that you kept talking about always having two keys but never explainkng how to do that. I also didn't realise that they're completely seperate, I always thought it was a clone of the first one so this has clarified a lot. We need more videos like this where we get baby-ed through exactly how to do it and with all the information so that we can feel comfortable using them.
@xileets Жыл бұрын
Took advantage of the yubi-deal last time. Mad good deal to get multiples. Thx Shannon!
@z1kk9 ай бұрын
so am i understanding this correctly; you need to set up each account for every yubikey you intend to use interchangeably? basically set up 2fa twice every time in most instances?
@yippeethreeeightАй бұрын
Thank you for this video. I couldn't figure out how to set up OATH on two devices. Luckily, I was able to plug both of them into my desktop and add that account to the Yubikey application for both keys, then continue. I never would have thought of that without this video.
@OinkPink1 Жыл бұрын
Hey Shannon, thanks for these yubikey videos! I had always known about hardware keys but didnt have much knowledge on them. Once I saw your vids, I got two. Ps. I'd love to see a video on how to use a yubikey for a keepass db 😉
@ShannonMorse Жыл бұрын
Happy to help!
@DixonLu Жыл бұрын
Putting 2nd key in a safe place-->if traveling overseas, and I lost the key (or got robbed), my second key would be 5000 miles away 😢.
@supawiz6991 Жыл бұрын
Two is the recommended minimum. I have four keys myself. One stays in my desktop, two on my key chain (one for usb A and one UBS-C/Lightning) and one in my fireproof safe. If I’m traveling, one comes off my keyring and into either my laptop bag or suitcase. Both could still get stolen but the odds of that are very low.
@bluntdocto2571 Жыл бұрын
That why I have 2x Yubi keys, just like a real key
@Darkk6969 Жыл бұрын
@@supawiz6991 I wouldn't keep the key in the laptop bag as thieves always target them. Keeping it in a suitcase is a better idea so it's separate from your computer.
@AnonymousFreakYT Жыл бұрын
But if you got robbed of one, and have them in the same place, wouldn’t that make it likely that both would be stolen? “In a safe place” might even just be “in a separate piece of luggage while traveling.” If you’re on a long multi-destination business trip, just carry one on your keychain, the second in a locked pocket in your luggage. And put that second one in the hotel safe when you get there.
@ShannonMorse Жыл бұрын
This is the most logical answer.
@ALCY10 ай бұрын
what if you lose both the main and the spare keys?
@alternatuber66988 ай бұрын
Lol KABOOM!
@vwestTube Жыл бұрын
If I’m not mistaken UniFi doesn’t allowing for a second key to be registered
@estusflask982 Жыл бұрын
Unifi doesn't even allow you to use a physical key last time I checked
@vwestTube Жыл бұрын
@@estusflask982 Hm, I’ve used yubikey on unifi ubiquiti before I switched to other tipe of 2Fa, they may change their policies. Ill check it again later
@Sean_Cockrell Жыл бұрын
My UBNT account has my phone authenticator app and 2 Yubikeys all providing me with the same OTP code no problem. Setup "app authentication"
@estusflask982 Жыл бұрын
@@Sean_Cockrell The "app authentication" is TOTP, not FIDO.
@AnonymousFreakYT Жыл бұрын
Services that don’t allow two keys annoy me. Especially ones that insist on having SMS as “MFA” to add other methods.
@irokese4124 Жыл бұрын
Another problem is: even you have two hardware keys, some accounts only allow to register and use one key, for example PayPal.
@MarcosRobertoDosSantosJF11 ай бұрын
Exactly! I also have two keys, but Paypal only allow one.
@maccagrabme10 ай бұрын
Can you use the same key for more than one google account?
@neuideas4 ай бұрын
@@maccagrabme Yes, you can.
@williamwilliams770610 ай бұрын
Thanks, you are the first of many watched videos that explained that Google only has accommodations for 1 security key but will accept a second yubikey as a passkey and that is OK. I'm not very good with this stuff and I was a little worried that I did something wrong.
@ShannonMorse10 ай бұрын
I feel like that's a really important fact that a lot of folks don't know!! Glad it helped!
@アキラ-d5e Жыл бұрын
Thank you, Shannon. It's a informative video. But the coupon is not valid. Would you like to update it?
@bjorn98011 ай бұрын
An important security/privacy question. For example you have two accounts both use the same YubiKey. Can the provider see that you have a same security key aka signature?
@baby3339 ай бұрын
Smart question, ever figured it out?
@bjorn9808 ай бұрын
@@baby333 I ask Yubico, short answer was no. :)
@timeisnow332 ай бұрын
4:25 Hi, Shannon. Can you please explain the difference between pass key and 2fa keys? Like 2fa key generates codes every time you use it just like authenticator? Could you pkease explain that part.
@cx1291Ай бұрын
When you set up more than one Yubkey, does it have to be done at that moment rather than waiting a few months before making a second back up key? Great video
@texnolan47408 ай бұрын
Thanks for the info. Easy to follow.
@saturntwelve412122 күн бұрын
Great review, thanks! Isn't printing the QR codes creates a physical security vulnerability? Now they need to be stored and managed. The alternative is to revoke all past secrets and set up new ones which is a lot, I get it.
@darinjohnson3671 Жыл бұрын
Thanks was wondering about how to do this for the app for sites that do not support this.
@Klusio19 Жыл бұрын
My yubikey is coming to me tomorrow, only 1 however. I plan to buy one more soon, but I have question regarding that. I bought Yubikey 5 NFC (black one). So I can use that to secure logging in to my Windows OS. Now, If I loose the black one, and let's say I have another one, BUT BLUE (so the cheaper version, which DOESN'T support securing logging into Windows), I still can't log in with the blue one, am I correct? So I'm basically locked out forever for my Window OS. (Except for the very last lifeline which are backup codes)
@MrSuperSnuiter Жыл бұрын
Hi Shannon all of the best for you and your family for 2024🙏🏻 73's and 88's
@warmgun4 ай бұрын
Do you need a pin? Can you use the Yubikey to sign in from any computer?
@jeffhale1189 Жыл бұрын
Thanks for sharing. Blessings on your day!
@philorton194010 ай бұрын
Shannon, thank you for the great videos. FYI, I tried to get your discount at Yubikey on the 5 NFC key with USB C . They would not apply to my order. However they would allow for the USB A model. Not a big issue for me but just letting you know so that you don't lose sales credit in the future.
@ShannonMorse10 ай бұрын
They had to change how the code applied because someone kept putting it on a coupon site 😕
@wrighty663110 ай бұрын
Thanks Shannon the bit of printing the QR code was genius I’ve printed out with back up codes when they were available and added all my accounts to both of my keys.Can I ask do you know how to change the pin on windows/pc as that’s the only time it seems to be required when using the keys to log in on accounts and I’ve not set up a pin on the key itself
@ShannonMorse10 ай бұрын
Glad it was helpful!
@aremdashvili10 ай бұрын
Thanks, you helped me a lot!! ❤
@imthestein Жыл бұрын
Just so you know I tried using your link because I wanted to get some spares and it doesn't work regardless the browser I try it in
@ShannonMorse Жыл бұрын
Ooo thank you, the coupon code should work fine on yubicos website tho!
@shadowtabbys Жыл бұрын
I use the black ones and the blue, the blue is back up though and my black is for windows and sites as well.
@pixlatdguardian1489 Жыл бұрын
Another thing I have done is put the TOTP secret into my password manager, and I can add a new yubikey without having to have a printed copy.
@DavidHanniganJr Жыл бұрын
What's the difference between a passkey & a 2FA let?
@jimwheeler727711 ай бұрын
Hi Shannon...wondering if you know: Does a yubikey have to be "ejected", like any other usb drive? or can it just be pulled out?
@ShannonMorse11 ай бұрын
In my experience, I just remove it. Never had an issue.
@frankkucienski5067 Жыл бұрын
Thank you for these great videos. My work is about to supply us with a yubi key for our work computes but I had a Question? If I setup a yubi key for my laptop do I need one for my phone to access the the apps? for example my bank app vs my bank website?
@Oemford918 күн бұрын
your smokin, thanks for the Yubikey info, your the hak5 babe, that show was so awesome ive watched everyone.
@TheConservativeTalkingPoint Жыл бұрын
I have a question. I want to go passwordless on outlook 365, personal account. How can I do this without the MS authenticator app? I just want to use my key ONLY to login, otherwise what's the point of the security? How do you accomplish this?
@BDBD16 Жыл бұрын
Yubi has a walkthru on their webiste look for passwordless entra ID via the googs should be first hit.
@town728 ай бұрын
? can an adapter be used if the key has a different connection...
@MikeMontgomery111 ай бұрын
I use Roboform, will the Yubico key work with it or does it not matter?
@How-to-by-Lou5 ай бұрын
Is it one key per website.. Or can one key be used for multiple sites?
@ShannonMorse5 ай бұрын
One key can be used for multiple sites!
@GhenaLopez-o9z7 ай бұрын
Hi what can I do my yahoo account is lock and is asking me for for a back up number I never was able to access it? Please help.
@mattv5281 Жыл бұрын
How secure is logging into other sites with your Google account? Google is one of the few that implements hardware 2FA well. Would logging into other services via Google make them more secure? I don't really understand the protocol that lets this happen. How much info from my Google account can those other services see? Or is it better just to keep everything separate?
@estusflask982 Жыл бұрын
Using the key to login with Google on other websites/apps doesn't change what data the other websites can see.
@SiliconRiot Жыл бұрын
I always worry about USB drives and Ubikey’s little contact tabs being exposed and damaged..? Any info on that..?
@estusflask982 Жыл бұрын
They may look damaged because of the oxidation on them, but that's how they look even if they are enclosed in a metal housing. It doesn't mean they are damaged.
@aleckane99 Жыл бұрын
You mentioned that these keys cannot be copied, I wonder if that would be possible with a MITM attack. Any thoughts on that as a possibility?
@Summerbunny15 Жыл бұрын
If the key codes were copied in a man in the middle attack, Yubikeys also provide an extra layer of security in that you have to physically tap the key to complete authentication, so a hacker would not be able to use the code to log into your websites unless they physically had access to your Yubikey.
@AFA92T385 ай бұрын
Are there any negatives to NFC (seems like same $55 price with and without)? ie can hackers use something to skim it in a public place? If you are using with a Lightning phone, can you pull codes via the app via NFC if not using a ci version? Do your primary and spare keys have any benefit of being exact same, same series, or type? eg $55 Primary 5C NFC which should work in most modern iOS systems, and a $29 Security C or C NFC as spare? Thanks!
@David_L3 Жыл бұрын
Thanks for this. I picked up 3 yubikeys during black friday sales (A + C + one bio at full price). I'm torn between yubikey and google authenticator when both options are available. I use the transfer option to keep an authenticator backup on an old phone.
@L4d31r410 ай бұрын
I saw that it is possible to use Yubikey to access Windows (offline /local machine user only). The question is: what about access to HD? In this case, with more advanced techniques, they would be able to obtain the data from the independent HD, right?
@vaanea290 Жыл бұрын
Subbing to the channel because of this video,... just seeing if this helps in what direction the channel is headed.
@hastingb Жыл бұрын
I've been using a couple of hardware keys for the last year or so. I'm wondering what is stored on the hardware key after I secure an account. Do I need to worry about storage space or removing anything if I close the account?
@baby3339 ай бұрын
Inspired me to buy one! (Two actually XD), also love the hair! :)
@itsawave312710 ай бұрын
I was trying to set up my backup yubikey and it looks like Google security has changed and you can no longer add multiple keys to 2fa, any solutions or am i missing something?
@mike8080810 ай бұрын
There are ways to literally clone yubikeys. It involves setting the underlying "seed" value that encrypts and anchors all of the other keys (secrets) you _derive_ from the master seed value on the device. What this means is that for every key you setup with your yubikey, the others are automatically able to generate any of the derived keys because the cloned devices all have the same seed value/key.
@0nceuponatime486 Жыл бұрын
Question: Can we add 4 keys of the same log in type. For example I travel a lot. I want 2 keys with me and 2 keys with my best friend back home. Can we do 4 keys via passkey/2fa. The way you explained it made it seem like we can only have 1 for pass key and 1 for 2fa. Which means only 2 back ups (I could easily loose both while travelling).
@DAVIDGREGORYKERR7 ай бұрын
The version of Chrome Browser I am running doesn't support YUBIKEYS at the minute.
@ericthenomad19 күн бұрын
what if you lose all your keys? then you lose access to logging into your youtube account forever?
@Oemford918 күн бұрын
why does Steam not use Yubikeys for 2factor?
@crc-error-7968 Жыл бұрын
thank you! thank you! thank you! 😄
@chrisichris10006 ай бұрын
do you set up more than 2 (multiple) keys the same way?
@ShannonMorse6 ай бұрын
Yes, each additional key would be set up using the same process.
@knowbot11 ай бұрын
This link is not valid.😢
@miguelb7789 ай бұрын
I have been trying to add additional yubikeys to my goggle accounts, but the prompt is not there anymore unlike before that I could keep adding keys. Comments please?
@Nadox15 Жыл бұрын
Is it possible to use some kind of 3-way authentification, password, phone (via sms or google auth) + yubikey?
@baby3339 ай бұрын
Most (if not all) sites generally let you in at 2 Authenticators EVEN if you have 3+ enabled. (stay away from enabling SMS, its only a security concern tbh) Some (let's say ProtonMail) you can have almost up to 3-4-way authentications XD (Pin + Password + TOTP + Two Password) Also some Crypto exchanges websites might use 4 Auths on withdrawls. ( Password, Fund Password, TOTP, Email & then you must prove you're not a robot XD)
@ams1393410 ай бұрын
Can you help me understand what happens if you were to lose both keys in a housefire? Assuming you don't have any family or friends you trust to keep a spare, and don't necessarily trust or know if it's safe to keep a spare in a bank safety deposit box? I'm at a loss for what happens if I lose access to both of my keys! I rent so i can't install a fireproof safe.
@ShannonMorse10 ай бұрын
Make friends? Bury one in a cave? Save your backup codes digitally? I'm sure we could say "but the planet might freeze over!" but I'm sure you can figure something out for your specific scenario 😉.
@ams1393410 ай бұрын
@@ShannonMorse ahhh thank you! Can you talk about your third option - save your backup codes digitally? I don't understand what the backup codes are here. Thanks again!
@ShannonMorse10 ай бұрын
Here ya go! kzbin.info/www/bejne/ZprUYXWdnrCfja8si=JlQy2jT3J30M2qR5
@Panicthescaredycat10 ай бұрын
Oh my god, we can use the same QR code?! I'm new to yubikey's and i thought i had to re-setup all of the codes and everything if i got new keys.......... omg that's sick!!
@ShannonMorse10 ай бұрын
Yes!!! Just securely store the QR code or authenticate all your yubikeys before clicking away from the QR code! You only see the code once on the screen but it's a great hack!!
@Panicthescaredycat10 ай бұрын
Yea!! but i was planning on getting more, i currently have 2, and i was like uggghh i have to remove my 2fa and re do all the keys again.. but i just screenshotted the QR codes isntead now and stored them temporarily! @@ShannonMorse
@svenlima4 ай бұрын
This means that with such a security key I don't need a different password for every site I want to register? I can use my 1234-Password?
@mr.wigglemunch385611 ай бұрын
If I have two Yubikey's, recovery codes and the authenticator app, is it wise to remove the rest of the authentication methods like email and phone number verification? Also, in theory, if a hacker would simswapps my phone number, could he or she change all the other authentication methods in my Google account and make the first methods I mentioned useless?
@epotnwarlock Жыл бұрын
how could you use this with an authenticator app? and is there a further backup if both keys (or if someone only has 1 key) is lost?
@ADHJkvsNgsMBbTQe Жыл бұрын
In some cases you can use the same QR code to set up authentication by more than one authenticator app (e.g., Authy, Yubico Authenticator, Google Authenticator, Microsoft Authenticator, 1Password, Apple Passwords, and so on). Each app has different strengths or weaknesses (for example, if you set up another device on the same account, does it automatically grant access to your credentials? A comparison of these is probably a whole separate video). You can also store a screenshot of the QR code as an attachment in 1Password, for example, in case you need to set up another key later. If you want to be extra careful, you could encrypt the screenshot file before attaching it in your password manager (or before saving it in some other secure location).
@MackenzieHorn Жыл бұрын
Once I setup keys should I turn off the other Google methods like phone verification?
@ShannonMorse Жыл бұрын
I would. Anything is better than nothing, but hardware keys are the most secure option, so removing the other options would be best since they could be used as alternatives modes to login
@JunkheadAlice Жыл бұрын
While researching YubiKeys I noticed that Google is involved in their development. Given Google's privacy track record and that part of my security measures involve being as Google free as possible, is it possible to trust these keys or are there better alternatives?
@JunkheadAlice10 ай бұрын
@TorchCTI I still don't trust them regardless and would like to find a non Google alternative.
@roobscoob477 ай бұрын
Thanks, Shannon~
@SSJ0016 Жыл бұрын
They should be sold in pairs IMO. Or at least provide a discount for buying two!
@ShannonMorse Жыл бұрын
My discount stacks for each one you buy.
@domantlen6231 Жыл бұрын
If Yubico sponsor you please tell them that yubico-luks seems like dying and decrypting LUKS partitions/disks with yubikey is a mess (partially also because of systemd)
@vincorsaro5 ай бұрын
One thing I haven't understood yet and that no one talks about is whether these credentials are freely accessible, that is, if I steal your Yubikey can I access all your accounts? If that were the case, in my opinion it wouldn't be so safe after all.
@ShannonMorse5 ай бұрын
No, because you're also protecting your accounts with a username and password, and hopefully all your passwords are unique. A thief can't do anything with a yubikey by itself. It won't even work unless they also have access to your account credentials and chances are very low that this would be the case. If you're a target who needs to worry about this, id recommend upgrading to a biometric key.
@ReynoldsGroupRadio Жыл бұрын
So what happens if I only have the one key and lose it? Am I locked out of the account permanently?
@just__mike Жыл бұрын
Yep.
@kissu_io7 ай бұрын
Backup codes is still a way.
@Hullj Жыл бұрын
When I need to deal with these things, I Google the various stuff like OTP and 2fa and Fido and then I probably forget what they are. I would appreciate it if you would tell us what those are when you mentioned them in your videos. It's helpful. And yes, I got two UB keys just like you said
@ShannonMorse Жыл бұрын
Here ya go! kzbin.info/www/bejne/rZC8n2SadtZ_hZosi=vkDJR3ByZXWA0JzC&t=116
@Hullj Жыл бұрын
@ ShannonMorse That's the present situation as I said. Saying "two factor authentication or TFA" the first time it comes up is a lot more efficient than asking a lot of people to Google stuff when they only need a prod.
@ColoRadio6996 Жыл бұрын
Antie EM!, Auntie EM!
@jamesedwards3923 Жыл бұрын
I have way more than two FIDO keys. Depending on the standard and brand. $500 can afford you many keys. Half that can get you a decent amount.
@bheathrow Жыл бұрын
Korbin Dallas MultiPass.
@AlphaBravo86011 ай бұрын
Google titans only $35 and NFC compatible
@fastbobby5049 ай бұрын
Was surprised by your saying that you don't need your key every time you log into a site. I have not found this. Today I logged into my bank site looking to set that up. I used my key and I was brought straight into the site, no place to click to remember the browser, etc. The key I'm using is not Yubi, its a different brand.
@ShannonMorse9 ай бұрын
Hi, it depends on the website. I explained this in much more detail in my video about how cookies work: kzbin.info/www/bejne/rpLPmGuXaMp8r5Y - banks generally do require you to re-authenticate after shorter periods of time, or every time you close your browser or leave their site.
@Knards Жыл бұрын
Shannon convinced me to get 2 Yubiceys, but I really subscribed for her hair (jk) The only thing I dont like is when you have an app like Acronis that only supports 1 autheticator device. then I have to go to my other computer, get that key and plug it in.
@lyianx11 ай бұрын
So in other words. If i alerady setup my account on one of them, and want to setup a second, i have to remove the ones i Just setup , and do them both at the same time.. *sigh* well that can be a massive pain if you have alot of accounts tied to them.
@lyianx11 ай бұрын
Also, how do you revoke just One of the keys?
@CanesFan65 Жыл бұрын
Better buy 3 or 4. I've had several Yubikeys stop working over the past couple years. Not to mention then you may need a USB-A, a USB-C and an NFC Yubikey.
@maccagrabme10 ай бұрын
So if you have this situation cant you sign into the account using the working key and delete the key that isnt working and then buy another one and setup your backup again?
@crackjoker-yb8jp8 ай бұрын
Buy a ledger hardware wallet. If you lose it just buy another ledger, enter your seed phrase and voila. Your hardware 2fa is tied to your seed phrase.
@Blake219Blake2 ай бұрын
Your instructions don't work for OATH-TOTP. The Yubi Athenticator app says that an account by that name already exists when I try to make the second key.. Also, you never explain how to use the copy of the QR code that I either print or save a screen shot of. How do I make the second key with them? More details, and a little longer shots of the screens would make this video more useful, if your advice works.
@janokartal5690 Жыл бұрын
Nice one 😊
@mattv5281 Жыл бұрын
PayPal only lets you set up one single key. I don't use it anyway, ao i might just close my account.
@estusflask982 Жыл бұрын
Paypal lets you use one key and one TOTP code. Better than most apps.
@LionRoars918 Жыл бұрын
Just make the 2nd key identical to the 1st one using the Yubikey software.
@estusflask982 Жыл бұрын
That is not possible, since you have to first register the key with the app/service you want to use it with. Although, you can have the same TOTP code on multiple Yubikeys.
@McTroyd Жыл бұрын
Holy cannoli, Shannon! Sponsored by Yubico?! That's awesome. I need a couple replacement keys anyhow... 👍
@JyjuiaYjsiv8 ай бұрын
Ola, yubikay é melhor q o passkey q a google lançou se sim pq.😊
@thestreamreader Жыл бұрын
My mom's been using a hand written password notebook for last 20 yrs ha.
@GdncHfjbdkf5 ай бұрын
Im sorry in Las Vegas i did not see darren kitchen you there during 11/06/2022 - December 12/14/2022: A look a like pretended to be you at Starbucks at the S Maryland Parkway Starbucks accross from El' Combron near UNLV i got rid of all of my tech which i never used: Bash Bunny 1/2 , Lan Turtle, Lan lady Bug, Wifi PineApple mach 7, and key Croc to show i wasn't gonna do something dumb, i did that because i thought i was giving back my Hak5 gear to you but that was a look alike! In front of the Starbucks Cameras looking directly at it getting ride of my never used tech from Hak5 because i don't know how to! Plus even if i did; I wouldn't utikise them in a illegal way! Ever! I'm being setup!
@oc2699Ай бұрын
bad key its so bad , i lost all my account because i forget PIN Code so i can open my accounts gmail
@GdncHfjbdkf5 ай бұрын
Replay attack on a yubikey when password on a yubijey is known and a threat actor is targeting someone, create lab to test yubikeys and gmail google accounts in a cafe like scenario mitm
@zine_eddinex2411 ай бұрын
❤
@maxxmich Жыл бұрын
do t lose it in the first ace.. and put it on a keychain...
@DAVIDGREGORYKERR7 ай бұрын
I wonder why a Raspberry Pi can't be programmed to operate as a YUBIKEY.
@salty6pence672 Жыл бұрын
Love the new content. I Kinda feel like Darren should have given you the show. You kept it alive for years while he seemed absent.
@ShannonMorse Жыл бұрын
Years ago he offered me a co-ownership. I declined as owning a hacker channel comes with a lot of negative bias and legal issues. I'm glad I've decided to work on my own solo career, it's very freeing.
@ecotts5 ай бұрын
So you're basically giving Google your key.
@jamielannister96309 ай бұрын
Are you serious buy two expensive keys. These keys may have a good purpose, but are over priced for old styled tech.
@nokianinja9 ай бұрын
Primary key and FOREIGN key. 😌 Y'know in case you lose it in a foreign country. 🤭
@dtnlivinglife67318 ай бұрын
Thanks for the Info, and nice video, easy to follow. Scenario, Husband & Wife and a spare, three keys. We both have different websites and yet would like to have a spare. Do we have to have four keys or is there a way to make three work? You mentioned the storing of the QR Code. Where are you suggesting to store this security information? Do you use a password manager, if so who? and to let you know you get two subscribers for the price of one... This account (KZbinr) and my Tex.Nolan account! LoL ~ Tex