YubiKey Gains iOS SDK to Enable Secure 2FA Logins in Select Apps Using NFC

by

Yubico is a company that sells the "YubiKey," a small piece of hardware that protects access to computers and online accounts by providing strong two-factor authentication in lieu of receiving a text message code on a smartphone or other 2FA steps. With the NFC-equipped YubiKey NEO, Android users have been able to authenticate their log-ins with a tap, and this week Yubico announced that ability has launched for iPhone users as well (via The Next Web).

yubikey neo ios
With the launch of the YubiKit 1.0.0 iOS SDK, the company is allowing developers to add support for the YubiKey NEO into their iOS apps, starting with sole support from LastPass. Once set up with a LastPass account, the YubiKey NEO generates a one-time password, and when the user gets to the 2FA log-in screen, they simply tap the NEO near the back of the iPhone to authenticate.

It has been possible for developers to integrate with YubiKey NEO since iOS 11 launched in September, but the debut of the SDK should lead to wider adoption since it will be far easier for developers to introduce support for the device's NFC abilities.

The NEO does not require a battery to function, nor does it need network connectivity, and Yubico says that it is "four times faster" than typing a traditional one-time passcode. In addition to NFC, the device has a dongle for USB-A connectivity so it can double as an authenticator on laptop and desktop computers, and Yubico says that it's crush resistant and waterproof.


The YubiKey NEO is supported on iPhone 7 devices and newer, and for LastPass the feature is supported under the Premium, Families, Teams, and Enterprise subscription tiers. Yubico hasn't yet revealed which apps might next launch support for the YubiKey NEO on iOS devices. YubiKey can already securely log users in on macOS 10.12 or later, and the product integrates with hundreds of services and applications online.

Those interested can purchase the YubiKey NEO from the company's website for $50.

Top Rated Comments

archer75 Avatar
35 months ago
Just doesn't work with enough services I actually use. At a minimum amazon needs to support it. And of course more online stores and services.
Score: 1 Votes (Like | Disagree)
Jsfrederick Avatar
35 months ago

The Yubikey can implement multiple schemes. One protocol here is called Yubico OTP. This is a Yubico proprietary HOTP-like scheme, and relies on a shared secret held by Yubico. It is a one-way protocol, which means that it can be handled via iOS's read-only NFC support. It is broadly similar to OATH HOTP, but again, to eliminate provisioning, it, by default, relies on a shared secret installed and held by Yubico and their verification servers. (You can overwrite this with a custom server and verify yourself). The major weakness of this scheme is that it is not resistant to man-in-the-middle attacks.

OATH HOTP is a second option. That is the event-based Authly/Google Authenticator. It requires individual provisioning, does not require a trusted third-party, but does nothing to protect against MITM.

The Yubikey can also implement U2F, which does protect against man-in-the-middle attacks. However, U2F requires two-way communication with the fob, which cannot be done with the current NFC framework in iOS. The solution is that there are a number of BLE U2F tokens, which do work with iOS.

In my opinion, because Yubico OTP is obsolete. It relies on Yubico's servers and secrets and does not protect against MITM like U2F does. It is similar to other services now gone (Symantec VIP).

konqerror, you analysis is SPOT ON! YubiOTP is still a "shared secret" solution. Yubico has taken the shared secret model about as far his it can. It's really a combination of both HOTP and TOTP, there is a counter element and a time element, as well as some other data that is incorporated into the OTP that is genereated. Self Hosted OTP validation server is rather easy, that's what I do at home.

Completely agree that U2F is much better. It's a modern, asymmetric encryption solution. Unfortunately, it only works with web based services today, and requires a web browser that understands U2F. Currently only Chrome and Firefox. FIDO2 should remove these limitations and open up this functionality to not web services. I am looking forward to having FIDO 2 support for everything!

I also hope that Apple will open up the NFC interface to third party developers soon. That would be a great win for ALL customers.

I have looked at the BLE stuff. Still not as easy to use as the Yubikey. Requires a battery, and are considerably thicker that the Yubikey. I still have my original Yubikey I purchased in 2009. Still works, even after being washed at least twice.
Score: 1 Votes (Like | Disagree)
archer75 Avatar
35 months ago



Absolutely! That is a big issue. I request Yubikey support for every service I use. Have been asking my bank for YK support for many years. I finally got some traction over the last few months. Let's see what happens...

I have actually been successful in some cases with the requests. Many times, it's just that the services does not know about the Yubikey value. I have and conversations with a number of services and discuss this topic. Not all are open to the idea, but some are.

That's a good idea. I'll get a hold of my credit union. They seem very interested in adopting new technologies. Even though yubikey isn't new.
I'm surprised Chase isn't on the list. Or other major banks.
Score: 1 Votes (Like | Disagree)
Jsfrederick Avatar
35 months ago

Never heard of YubiKey before, and since reading this I’ve done a little research. I have been using Authy up until this point, which I only have running on my iPhone (and not the chrome extension on macOS, as an example).

Is YubiKey far more secure than Authy? What are folks personal experience with using YubiKey on various websites? Have you completely replaced an authenticator app with YubiKey?

Also, does YubiKey work with Brave browser on macOS? I’ve seen reviews where it only works on Chrome, yet I’ve seen it mentioned on GitHub it has been in development for a couple years now.

In my opinion, yes the Yubikey is more secure. First, it's an external hardware token with a cryptographic engine on it. Authy (and Google authenticator, as well as others) use a "shared secret" That means that the web site you log into has your shared secret. If that is compromised, then all bets are of. Yubikey uses U2F, which is a public/private key solution. The web site does NOT have the secret key, only the public key. Even if they get your public key, a hacker cannot log in without your private key.

The YK also standard standardOTP (similar to Authy), as well as an enhanced Yubico OTP. As long as the web site supports Yubico OTP or U2F, you are good. OTP is independent of the web browser, it is based in the web site. U2F does require a compatible browser. Right now Chrome and Firefox are the only ones to support it. Hopefully Safari will be coming soon. MS will provide Edge support soon also.
Score: 1 Votes (Like | Disagree)

Top Stories

bloodoxygenapplewatch

Apple Watch Series 7 Rumored to Feature Blood Glucose Monitoring

Monday January 25, 2021 5:05 am PST by
The Apple Watch Series 7 will reportedly feature blood glucose monitoring via an optical sensor, according to ETNews. The report, which mainly focuses on the blood glucose capabilities of the Samsung Galaxy Watch 4, explains that Apple is intending to bring blood glucose monitoring to the upcoming Apple Watch Series 7 using a non-invasive optical sensor. Measuring blood glucose levels,...
14

Apple Releases iOS 14.4 and iPadOS 14.4 With New Camera Warnings and Bug Fixes

Tuesday January 26, 2021 10:04 am PST by
Apple today released iOS and iPadOS 14.4, the fourth major updates to the iOS 14 operating system that was initially released in September. iOS and iPadOS 14.4 come more than a month after the release of iOS and iPadOS 14.3, updates that brought new emojis, Intercom support, and more. The iOS and iPadOS 14.4 updates can be downloaded for free and the software is available on all eligible...
7

Apple Releases watchOS 7.3 With Unity Watch Face, Expanded ECG Availability and More

Tuesday January 26, 2021 10:03 am PST by
Apple today released watchOS 7.3, the third major update to the watchOS 7 operating system that was released in September. watchOS 7.3 comes more than a month after watchOS 7.2, an update that brought support for Apple Fitness+ ‌‌The watchOS 7.3 update‌‌ can be downloaded for free through the dedicated Apple Watch app on the iPhone by going to General > Software Update. To install...
14

Apple Releases tvOS 14.4 for Fourth and Fifth-Generation Apple TV Models

Tuesday January 26, 2021 10:02 am PST by
Apple today released tvOS 14.4, the fifth update to the tvOS 14 operating system that was initially released back in September. tvOS 14.4 comes more than a month after the release of tvOS 14.3. tvOS 14.4, which is a free update, can be downloaded over the air through the Settings app on the ‌Apple TV‌ by going to System > Software Update. ‌‌‌‌Apple TV‌‌‌‌ owners who have...
14

Apple Releasing iOS 14.4 and watchOS 7.3 Later Today

Tuesday January 26, 2021 7:20 am PST by
In its Black History Month announcement this morning, Apple has confirmed that iOS 14.4 and watchOS 7.3 will be released later today. watchOS 7.3 expands the ECG app on the Apple Watch Series 4 and newer to Japan, Mayotte, Thailand, and the Philippines, while iOS 14.4 introduces a notification on iPhone 12 models with non-genuine cameras. Both software updates also add support for a new...
AirPods Pro Gen 2 Feature2

Second-Generation AirPods Pro Widely Rumored to Launch in First Half of 2021

Tuesday January 26, 2021 8:24 am PST by
Apple plans to release second-generation AirPods Pro within the first half of 2021, according to unnamed industry sources cited by Taiwanese publication DigiTimes in a report focused on flash memory supplier Winbond. From the report:Winbond is also expected to be among the NOR flash suppliers for Apple's next-generation AirPods Pro slated for launch later in the first half of this year, the...
apple watch black unity

Apple Celebrates Black History Month With Limited-Edition Watch, Featured Apps and Books, and More

Tuesday January 26, 2021 6:14 am PST by
Apple today announced that it will be celebrating Black History Month with curated content that highlights and amplifies Black creators, artists, developers, and businesses across the App Store, Apple Music, the Apple TV app, Apple Books, Apple Podcasts, and more. The content will be featured throughout the month of February. Black Unity Sport Band has "Truth. Power. Solidarity." ...
magsafecasedangle

Apple Elaborates on Potential for iPhone 12 and MagSafe Accessories to Interfere With Implantable Medical Devices

Saturday January 23, 2021 2:42 pm PST by
Since the launch of iPhone 12 models in October, Apple has acknowledged that the devices may cause electromagnetic interference with medical devices like pacemakers and defibrillators, but the company has now shared additional information. Apple added the following paragraph to a related support document today:Medical devices such as implanted pacemakers and defibrillators might contain...
14

iOS 14.4 Patches Vulnerabilities That May Have Been Actively Exploited

Tuesday January 26, 2021 12:16 pm PST by
Apple today released iOS 14.4 and iPadOS 14.4, and along with a handful of minor new features, the software introduces security fixes for three vulnerabilities that may have been used in the wild. According to a security support document shared by Apple, there were kernel and WebKit vulnerabilities affecting all iPhones and iPads running iOS or iPadOS 14. The kernel vulnerability could allow ...
matte black macbook pro colorware

Apple Researching High-End Titanium MacBook Casings With Unique Textured Finish

Tuesday January 26, 2021 7:10 am PST by
Apple is researching the use of processed titanium with unique properties for future MacBooks, iPads, and iPhones, according to a newly-granted patent application. In a filing titled "Titanium parts having a blasted surface texture," granted by the U.S. Patent and Trademark Office and spotted by Patently Apple, Apple explains how various devices could adopt titanium casings with a...