LWN.net Logo

Fedora accepting YubiKey one-time passwords

Fedora accepting YubiKey one-time passwords

Posted Oct 15, 2010 17:41 UTC (Fri) by joey (subscriber, #328)
Parent article: Fedora accepting YubiKey one-time passwords

"The key never touches the drive during the burning process [so the] attack window here, while real, is very tiny."

From looking at the script, that's not really true, since it does not lock its memory the key could be written to swap.

But that's a minor problem compared to the fact that the key is exposed for all local users to see in the parameters to the ykpersonalize program ...


(Log in to post comments)

Fedora accepting YubiKey one-time passwords

Posted Oct 27, 2010 12:53 UTC (Wed) by salimma (subscriber, #34460) [Link]

Local users with root access, I suppose. Which is why setting up the key on a public machine is not recommended :)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds