Wiki source code of YubiKey Set-Up And Use: Two Factor Authentication Using Hardware (YubiKey) Secure Google, Bitwarden, LastPass
Version 15.1 by Doug Sargent on 2023/03/30 11:10
Show last authors
| author | version | line-number | content |
|---|---|---|---|
| 1 | {{toc depth="7" start="1"/}} | ||
| 2 | |||
| 3 | === {{id name="Overview"/}}**Overview** === | ||
| 4 | |||
| 5 | Your YubiKey is the size of a thumb (flash) drive and plugs into the same place (USB port) on your laptop. | ||
| 6 | |||
| 7 | [[image:attach:securitykeyanfc-keyring.jpg||original-height="500" data-xwiki-image-style-alignment="center" original-width="600"]] | ||
| 8 | |||
| 9 | Pressing or tapping button is done with a light touch especially when plugged into a port. | ||
| 10 | |||
| 11 | [[image:attach:yubikey-5-tap-720x720_1_3-5.jpg||original-height="720" data-xwiki-image-style-alignment="center" width="680" original-width="720"]] | ||
| 12 | |||
| 13 | [[https:~~/~~/www.yubico.com/why-yubico/how-the-yubikey-works/>>url:https://www.yubico.com/why-yubico/how-the-yubikey-works/||data-card-appearance="inline" shape="rect"]] | ||
| 14 | |||
| 15 | **YubiKey** is a hardware device that makes **two-factor authentication** as simple as possible. | ||
| 16 | |||
| 17 | **It doesn’t require a smartphone.** **But it can be used with a smartphone.** | ||
| 18 | |||
| 19 | Instead of a code being texted to you, or generated by an app on your phone, you press a button on your **YubiKey **(plugged into your laptop). That's it. Each **YubiKey** has a unique code built on to it, which is used to generate codes that help confirm your identity. | ||
| 20 | |||
| 21 | When logging in to Google (or any other **YubiKey** secured application) simply insert the key into the USB port of your laptop and gently press the golden button on the **YubiKey** when prompted by the secured app. | ||
| 22 | |||
| 23 | **YubiKeys** can be used with an Android or iPhone along with a laptop. Access is granted by tapping the key on the phone as long as a **YubiKey with NFC** (near field communications) is used. Works similar to paying at a cash register by tapping your phone (Tap To Pay). | ||
| 24 | |||
| 25 | [[image:attach:image-20230329-191703.png||original-height="106" data-xwiki-image-style-alignment="center" original-width="266"]] | ||
| 26 | |||
| 27 | Yubico strongly recommend having a spare key. **No spare is needed for REMC1 accounts.** . **Ignore spare key instructions.** | ||
| 28 | |||
| 29 | //**If you lose your YubiKey or it ceases to work contact Support and we’ll take care of it.**// | ||
| 30 | |||
| 31 | **REMC1** administrates **Google**, **Bitwarden**, and **LastPass**, and can turn off 2FA on your account so you can get in, use your accounts, and re-setup your 2FA. | ||
| 32 | |||
| 33 | **Please note: REMC1** cannot support personal uses of your **REMC1 YubiKey**. | ||
| 34 | |||
| 35 | If you want to secure personal accounts such as your social media or finances, you are making a wise choice, but use your smartphone for free software 2FA or purchase your own hardware key and a backup key. | ||
| 36 | |||
| 37 | Here is a link to the hundreds of **YubiKey** supported products, services, and applications. | ||
| 38 | |||
| 39 | [[https:~~/~~/www.yubico.com/works-with-yubikey/catalog/?sort=popular>>url:https://www.yubico.com/works-with-yubikey/catalog/?sort=popular||data-card-appearance="inline" shape="rect"]] | ||
| 40 | |||
| 41 | === {{id name="Securing-Google-Accounts-With-Hardware-2FA-using-YubiKey"/}}**Securing Google Accounts With Hardware 2FA using YubiKey** === | ||
| 42 | |||
| 43 | Traditional login is no longer secure in today’s world – malware and other attacks steal passwords and hack accounts every day. The **YubiKey** is a hardware security key that provides strong one-touch authentication, and works seamlessly with **Google Accounts**. Fortify your login by turning on **Google 2-Step Verification** and registering the **YubiKey** with your **Google Account**. | ||
| 44 | |||
| 45 | ==== {{id name="Secure"/}}**Secure** ==== | ||
| 46 | |||
| 47 | By requiring the physical key to log in, you protect your account from remote and unauthorized access. | ||
| 48 | |||
| 49 | ==== {{id name="Easy-to-Use"/}}**Easy to Use** ==== | ||
| 50 | |||
| 51 | Get strong authentication with just a touch. Just log in to your Google Account, and tap the **YubiKey’s** gold contact when prompted. | ||
| 52 | |||
| 53 | ==== {{id name="Simple-YubiKey-Setup-For-Your-Laptop"/}}**Simple YubiKey Setup For Your Laptop** ==== | ||
| 54 | |||
| 55 | Click below link to enter **Google Account Security** for your own **REMC1** **Google Account.** | ||
| 56 | |||
| 57 | [[https:~~/~~/myaccount.google.com/security>>url:https://myaccount.google.com/security||shape="rect"]] | ||
| 58 | |||
| 59 | Scroll down to **How you sign in to Google** | ||
| 60 | |||
| 61 | [[image:attach:image-20230329-195455.png||original-height="493" data-xwiki-image-style-alignment="center" original-width="1220"]] | ||
| 62 | |||
| 63 | Click on **Security Keys**. | ||
| 64 | |||
| 65 | You will be prompted to login with your password. | ||
| 66 | |||
| 67 | Click on **Add Security Key.** | ||
| 68 | |||
| 69 | [[image:attach:image-20230329-195733.png||original-height="308" data-xwiki-image-style-alignment="center" original-width="1073"]] | ||
| 70 | |||
| 71 | Select **Physical.** And Click** Next.** | ||
| 72 | |||
| 73 | [[image:attach:image-20230329-195904.png||original-height="645" data-xwiki-image-style-alignment="center" original-width="743"]] | ||
| 74 | |||
| 75 | Select **OK.** | ||
| 76 | |||
| 77 | [[image:attach:image-20230329-200525.png||original-height="635" data-xwiki-image-style-alignment="center" original-width="725"]] | ||
| 78 | |||
| 79 | Select **OK.** | ||
| 80 | |||
| 81 | [[image:attach:image-20230329-201549.png||original-height="647" data-xwiki-image-style-alignment="center" original-width="737"]] | ||
| 82 | |||
| 83 | Insert your **YubiKey** into the USB port of your laptop. | ||
| 84 | |||
| 85 | [[image:attach:image-20230329-202116.png||original-height="651" data-xwiki-image-style-alignment="center" original-width="733"]] | ||
| 86 | |||
| 87 | **[ need actual Yubikey to demonstrate the finals pieces plus logging in ]** | ||
| 88 | |||
| 89 | A quick (1:18) video from Yubico (ignore spare key section) | ||
| 90 | |||
| 91 | [[https:~~/~~/www.youtube.com/watch?v=PeF0Y8pT7UQ>>url:https://www.youtube.com/watch?v=PeF0Y8pT7UQ||data-card-appearance="inline" shape="rect"]] | ||
| 92 | |||
| 93 | === {{id name="Securing-Bitwarden-With-Hardware-2FA-using-FIDO2-WebAuthn-with-YubiKey"/}}**Securing Bitwarden With Hardware 2FA using FIDO2 WebAuthn with YubiKey** === | ||
| 94 | |||
| 95 | **FIDO2 WebAuthn Overview – Why it's our way to use YubiKey with Bitwarden** | ||
| 96 | |||
| 97 | The YubiKey option is **OTP**. Choose **FIDO2 WebAuthn** option and use it with your **YubiKey.** | ||
| 98 | |||
| 99 | 2FA is evolving. Using email, SMS, or even **OTP** (one time password) for 2FA can be phished and/or hacked via a man-in-the-middle attack. **FIDO2 WebAuthn** to the rescue. | ||
| 100 | |||
| 101 | [[https:~~/~~/fidoalliance.org/fido2/>>url:https://fidoalliance.org/fido2/||data-card-appearance="inline" shape="rect"]] | ||
| 102 | |||
| 103 | [[https:~~/~~/fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-errata-20220621.html>>url:https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-errata-20220621.html||data-card-appearance="inline" shape="rect"]] part of **FIDO2** | ||
| 104 | |||
| 105 | [[https:~~/~~/www.w3.org/TR/webauthn/>>url:https://www.w3.org/TR/webauthn/||data-card-appearance="inline" shape="rect"]] **WebAuthn** | ||
| 106 | |||
| 107 | [[image:attach:image-20230330-125914.png||original-height="784" data-xwiki-image-style-alignment="center" original-width="426"]] | ||
| 108 | |||
| 109 | ==== {{id name="Setting-Up-FIDO2-WebAuthn-with-YubiKey-for-Bitwarden"/}}**Setting Up FIDO2 WebAuthn with YubiKey for Bitwarden** ==== | ||
| 110 | |||
| 111 | There are several 2FA methods that work with Bitwarden: (we use FIDO2 WebAuthn when use YubiKey) | ||
| 112 | |||
| 113 | Multiple enabled methods are supported. | ||
| 114 | |||
| 115 | [[image:attach:image-20230330-134316.png||original-height="757" data-xwiki-image-style-alignment="center" original-width="950"]] | ||
| 116 | |||
| 117 | ==== {{id name="To-setup-and-use-FIDO2-WebAuthn-on-your-Yubikey-for-Bitwarden-use-this-link."/}}To setup and use **FIDO2 WebAuthn** on your **Yubikey** for **Bitwarden** use this link. ==== | ||
| 118 | |||
| 119 | [[https:~~/~~/bitwarden.com/help/setup-two-step-login-fido/>>url:https://bitwarden.com/help/setup-two-step-login-fido/||data-card-appearance="inline" shape="rect"]] | ||
| 120 | |||
| 121 | === {{id name="Securing-LastPass-With-Hardware-2FA-using-YubiKey"/}}**Securing LastPass With Hardware 2FA using YubiKey** === | ||
| 122 | |||
| 123 | ==== {{id name="YubiKey-with-LastPass-Overview"/}}**YubiKey with LastPass** **Overview** ==== | ||
| 124 | |||
| 125 | [[https:~~/~~/support.lastpass.com/help/yubikey-multifactor-authentication-lp030020>>url:https://support.lastpass.com/help/yubikey-multifactor-authentication-lp030020||data-card-appearance="inline" shape="rect"]] **with LastPass** | ||
| 126 | |||
| 127 | ==== {{id name="Setup-and-Configure-YubiKey-with-LastPass-(Presently-only-uses-OTP)"/}}**Setup and Configure YubiKey with LastPass (Presently only uses OTP)** ==== | ||
| 128 | |||
| 129 | [[https:~~/~~/support.lastpass.com/help/how-do-i-set-up-and-configure-yubikey>>url:https://support.lastpass.com/help/how-do-i-set-up-and-configure-yubikey||data-card-appearance="inline" shape="rect"]] | ||
| 130 | |||
| 131 | ==== {{id name="Use-YubiKey-to-log-in-to-LastPass"/}}**Use YubiKey to log in to LastPass** ==== | ||
| 132 | |||
| 133 | [[https:~~/~~/support.lastpass.com/help/how-do-i-log-in-to-lastpass-and-autheticate-my-yubikey>>url:https://support.lastpass.com/help/how-do-i-log-in-to-lastpass-and-autheticate-my-yubikey||data-card-appearance="inline" shape="rect"]] |