Wiki source code of YubiKey Set-Up And Use: Two Factor Authentication Using Hardware (YubiKey) Secure Google, Bitwarden, LastPass
Version 19.1 by Doug Sargent on 2023/03/30 12:27
Show last authors
| author | version | line-number | content |
|---|---|---|---|
| 1 | {{toc depth="7" start="1"/}} | ||
| 2 | |||
| 3 | === {{id name="Overview"/}}**Overview** === | ||
| 4 | |||
| 5 | Your YubiKey is the size of a thumb (flash) drive and plugs into the same place (USB port) on your laptop. | ||
| 6 | |||
| 7 | [[image:attach:securitykeyanfc-keyring.jpg||original-height="500" data-xwiki-image-style-alignment="center" original-width="600"]] | ||
| 8 | |||
| 9 | Pressing or tapping button is done with a light touch especially when plugged into a port. | ||
| 10 | |||
| 11 | [[image:attach:yubikey-5-tap-720x720_1_3-5.jpg||original-height="720" data-xwiki-image-style-alignment="center" width="680" original-width="720"]] | ||
| 12 | |||
| 13 | [[https:~~/~~/www.yubico.com/why-yubico/how-the-yubikey-works/>>url:https://www.yubico.com/why-yubico/how-the-yubikey-works/||data-card-appearance="inline" shape="rect"]] | ||
| 14 | |||
| 15 | {{panel bgColor="#DEEBFF"}} | ||
| 16 | **YubiKey** is a hardware device that makes **two-factor authentication** as simple as possible. | ||
| 17 | |||
| 18 | It doesn’t require a smartphone. But it can be used with a smartphone. | ||
| 19 | {{/panel}} | ||
| 20 | |||
| 21 | Instead of a code being texted to you, or generated by an app on your phone, you press a button on your **YubiKey **(plugged into your laptop). That's it. Each **YubiKey** has a unique code built on to it, which is used to generate codes that help confirm your identity. | ||
| 22 | |||
| 23 | When logging in to Google (or any other **YubiKey** secured application) simply insert the key into the USB port of your laptop and gently press the golden button on the **YubiKey** when prompted by the secured app. | ||
| 24 | |||
| 25 | **YubiKeys** can be used with an Android or iPhone along with a laptop. Access is granted by tapping the key on the phone as long as a **YubiKey with NFC** (near field communications) is used. Works similar to paying at a cash register by tapping your phone (Tap To Pay). | ||
| 26 | |||
| 27 | [[image:attach:image-20230329-191703.png||original-height="106" data-xwiki-image-style-alignment="center" original-width="266"]] | ||
| 28 | |||
| 29 | Yubico strongly recommend having a spare key. **No spare is needed for REMC1 accounts.** . **Ignore spare key instructions.** | ||
| 30 | |||
| 31 | //**If you lose your YubiKey or it ceases to work contact Support and we’ll take care of it.**// | ||
| 32 | |||
| 33 | (% style="color: rgb(7,71,166);" %)**Please note: REMC1 cannot support personal uses of your** **REMC1 YubiKey**. | ||
| 34 | |||
| 35 | (% style="color: rgb(7,71,166);" %)If you want to secure personal accounts such as your social media or finances, you are making a wise choice, but use your smartphone for free software 2FA options or buy your own hardware key and a backup key. | ||
| 36 | |||
| 37 | {{panel bgColor="#DEEBFF"}} | ||
| 38 | Here is a link to the hundreds of **YubiKey** supported products, services, and applications. | ||
| 39 | {{/panel}} | ||
| 40 | |||
| 41 | [[https:~~/~~/www.yubico.com/works-with-yubikey/catalog/?sort=popular>>url:https://www.yubico.com/works-with-yubikey/catalog/?sort=popular||data-card-appearance="inline" shape="rect"]] | ||
| 42 | |||
| 43 | === {{id name="Securing-Google-Accounts-With-Hardware-2FA-using-YubiKey"/}}**Securing Google Accounts With Hardware 2FA using YubiKey** === | ||
| 44 | |||
| 45 | Traditional login is no longer secure in today’s world – malware and other attacks steal passwords and hack accounts every day. The **YubiKey** is a hardware security key that provides strong one-touch authentication, and works seamlessly with **Google Accounts**. Fortify your login by turning on **Google 2-Step Verification** and registering the **YubiKey** with your **Google Account**. | ||
| 46 | |||
| 47 | ==== {{id name="Secure"/}}**Secure** ==== | ||
| 48 | |||
| 49 | By requiring the physical key to log in, you protect your account from remote and unauthorized access. | ||
| 50 | |||
| 51 | ==== {{id name="Easy-to-Use"/}}**Easy to Use** ==== | ||
| 52 | |||
| 53 | Get strong authentication with just a touch. Just log in to your Google Account, and tap the **YubiKey’s** gold contact when prompted. | ||
| 54 | |||
| 55 | ==== {{id name="Simple-YubiKey-Setup-For-Your-Laptop"/}}**Simple YubiKey Setup For Your Laptop** ==== | ||
| 56 | |||
| 57 | {{panel bgColor="#DEEBFF"}} | ||
| 58 | Click below link to enter **Google Account Security** for your own **REMC1** **Google Account.** | ||
| 59 | {{/panel}} | ||
| 60 | |||
| 61 | [[**https:~~/~~/myaccount.google.com/security**>>url:https://myaccount.google.com/security||shape="rect"]] | ||
| 62 | |||
| 63 | Scroll down to **How you sign in to Google** | ||
| 64 | |||
| 65 | Click on **Security Keys** | ||
| 66 | |||
| 67 | [[image:attach:how I sign into Google.png||original-height="370" data-xwiki-image-style-alignment="center" original-width="915"]] | ||
| 68 | |||
| 69 | You will be prompted to login with your **Google** password. | ||
| 70 | |||
| 71 | Click on **Add Security Key** | ||
| 72 | |||
| 73 | [[image:attach:Security Keys.png||original-height="231" data-xwiki-image-style-alignment="center" original-width="805"]] | ||
| 74 | |||
| 75 | Select **Physical** and click** Next** | ||
| 76 | |||
| 77 | [[image:attach:add security key.png||original-height="484" data-xwiki-image-style-alignment="center" original-width="557"]] | ||
| 78 | |||
| 79 | Select **OK** | ||
| 80 | |||
| 81 | [[image:attach:security key setup.png||original-height="476" data-xwiki-image-style-alignment="center" original-width="544"]] | ||
| 82 | |||
| 83 | Select **OK** | ||
| 84 | |||
| 85 | [[image:attach:continue setup.png||original-height="485" data-xwiki-image-style-alignment="center" original-width="553"]] | ||
| 86 | |||
| 87 | Insert your **YubiKey** into the USB port of your laptop | ||
| 88 | |||
| 89 | [[image:attach:insrt key.png||original-height="488" data-xwiki-image-style-alignment="center" original-width="550"]] | ||
| 90 | |||
| 91 | **[ need actual Yubikey to demonstrate the finals pieces plus logging in ]** | ||
| 92 | |||
| 93 | A quick (1:18) video from Yubico (ignore spare key section) | ||
| 94 | |||
| 95 | [[https:~~/~~/www.youtube.com/watch?v=PeF0Y8pT7UQ>>url:https://www.youtube.com/watch?v=PeF0Y8pT7UQ||data-card-appearance="inline" shape="rect"]] | ||
| 96 | |||
| 97 | === {{id name="Securing-Bitwarden-With-Hardware-2FA-using-FIDO2-WebAuthn-with-YubiKey"/}}**Securing Bitwarden With Hardware 2FA using FIDO2 WebAuthn with YubiKey** === | ||
| 98 | |||
| 99 | **FIDO2 WebAuthn Overview – Why it's our way to use YubiKey with Bitwarden** | ||
| 100 | |||
| 101 | The YubiKey option is **OTP**. Choose **FIDO2 WebAuthn** option and use it with your **YubiKey.** | ||
| 102 | |||
| 103 | 2FA is evolving. Using email, SMS, or even **OTP** (one time password) for 2FA can be phished and/or hacked via a man-in-the-middle attack. **FIDO2 WebAuthn** to the rescue. | ||
| 104 | |||
| 105 | [[https:~~/~~/fidoalliance.org/fido2/>>url:https://fidoalliance.org/fido2/||data-card-appearance="inline" shape="rect"]] | ||
| 106 | |||
| 107 | [[https:~~/~~/fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-errata-20220621.html>>url:https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-errata-20220621.html||data-card-appearance="inline" shape="rect"]] part of **FIDO2** | ||
| 108 | |||
| 109 | [[https:~~/~~/www.w3.org/TR/webauthn/>>url:https://www.w3.org/TR/webauthn/||data-card-appearance="inline" shape="rect"]] **WebAuthn** | ||
| 110 | |||
| 111 | [[image:attach:image-20230330-125914.png||original-height="784" data-xwiki-image-style-alignment="center" original-width="426"]] | ||
| 112 | |||
| 113 | ==== {{id name="Setting-Up-FIDO2-WebAuthn-with-YubiKey-for-Bitwarden"/}}**Setting Up FIDO2 WebAuthn with YubiKey for Bitwarden** ==== | ||
| 114 | |||
| 115 | There are several 2FA methods that work with Bitwarden: (we use FIDO2 WebAuthn when use YubiKey) | ||
| 116 | |||
| 117 | Multiple enabled methods are supported. | ||
| 118 | |||
| 119 | [[image:attach:image-20230330-134316.png||original-height="757" data-xwiki-image-style-alignment="center" original-width="950"]] | ||
| 120 | |||
| 121 | ==== {{id name="To-setup-and-use-FIDO2-WebAuthn-on-your-Yubikey-for-Bitwarden-use-this-link."/}}To setup and use **FIDO2 WebAuthn** on your **Yubikey** for **Bitwarden** use this link. ==== | ||
| 122 | |||
| 123 | [[https:~~/~~/bitwarden.com/help/setup-two-step-login-fido/>>url:https://bitwarden.com/help/setup-two-step-login-fido/||data-card-appearance="inline" shape="rect"]] | ||
| 124 | |||
| 125 | === {{id name="Securing-LastPass-With-Hardware-2FA-using-YubiKey"/}}**Securing LastPass With Hardware 2FA using YubiKey** === | ||
| 126 | |||
| 127 | ==== {{id name="YubiKey-with-LastPass-Overview"/}}**YubiKey with LastPass** **Overview** ==== | ||
| 128 | |||
| 129 | [[https:~~/~~/support.lastpass.com/help/yubikey-multifactor-authentication-lp030020>>url:https://support.lastpass.com/help/yubikey-multifactor-authentication-lp030020||data-card-appearance="inline" shape="rect"]] **with LastPass** | ||
| 130 | |||
| 131 | ==== {{id name="Setup-and-Configure-YubiKey-with-LastPass-(Presently-only-uses-OTP)"/}}**Setup and Configure YubiKey with LastPass (Presently only uses OTP)** ==== | ||
| 132 | |||
| 133 | [[https:~~/~~/support.lastpass.com/help/how-do-i-set-up-and-configure-yubikey>>url:https://support.lastpass.com/help/how-do-i-set-up-and-configure-yubikey||data-card-appearance="inline" shape="rect"]] | ||
| 134 | |||
| 135 | ==== {{id name="Use-YubiKey-to-log-in-to-LastPass"/}}**Use YubiKey to log in to LastPass** ==== | ||
| 136 | |||
| 137 | [[https:~~/~~/support.lastpass.com/help/how-do-i-log-in-to-lastpass-and-autheticate-my-yubikey>>url:https://support.lastpass.com/help/how-do-i-log-in-to-lastpass-and-autheticate-my-yubikey||data-card-appearance="inline" shape="rect"]] |