Jose Enrique Hernandez
Jose Enrique Hernandez
Security Researcher, Founder, and Diver
May 18, 2008 2 min read

YubiCo and its YubiKey

thumbnail for this post

image

It is a member of the one time password initiative, this people are a defiantly a check out for future one time password solutions.
How does the YubiKey works and what does it do for me.

The Yubi key is basically a usb key(token)that you insert into your computer and when you hit the green glowing light on the usb key, it spits out a 44 character string that is your password. The 44 letter string is semi sudo random data. Which means it can be tgracked back to your key but it cannot be track or duplicated or reverse engineered. This is in essence a perfect unique password. This string is different every time you hit the green glowing button, so there is no worries of some key logging your password. Also portion of the string is 128 bit AES randomly generated number.

Now for uses, how can this be used. Well think car keys, think credit card authorization keys, think computer passwords, anytime of authentication method that requires a key and or password of any type can be replaced by one of this single keys. The only mystery requirement is that the receiving party of the string must have your key ID (part of the 6 first characters of the string) programed into it.


For more information check out: http://www.yubico.com/products/yubikey