Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Anyone know if its possible to use a Yubikey for sudo as well?


Yes it's possible ( https://www.ha-obsession.net/2017/05/u2f-sudo-fedora-25.html... and some other guides exists ) and I used it for about a year. I stopped using it. I was so annoyed to plugin the key every couple of hours that I simply kept the yubi key plugged in all the time - free to be picked by anyone and def. not increasing security.

We still use it for SSH and its great!


Leave the yubikey plugged in all the time. It's fine with respect to most threat models, provided you lock the graphical session when you are away from the computer.

If someone steals the key, they can't really do anything with it. They can't sudo because the session is locked. They can't use it to log in your web accounts from other computers because websites ask for a password/pin in addition to touching the yubikey.

PS: you should always have a backup yubikey (or, better, two)


You can also set the yubikey to require a pin before touching. The yubikey auto wipes it’s memory of the presented pin is wrong too many times in a row. So just leaving it plugged in is much more sensible in that case.


Yes, you’ll want the PAM module; either yubico-pam or pam-u2f.

https://developers.yubico.com/pam-u2f/

https://developers.yubico.com/yubico-pam/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: