Index | Thread | Search

From:
"Theo de Raadt" <deraadt@openbsd.org>
Subject:
Re: patch: stop login_yubikey(8) leaking OTP data to syslog
To:
Lloyd <ng2d68@proton.me>
Cc:
Theo Buehler <tb@theobuehler.org>, "tech@openbsd.org" <tech@openbsd.org>
Date:
Thu, 14 Aug 2025 15:27:44 -0600

Download raw body.

Thread
> If users only want FIDO functionality, they should be buying the Yubikey
> Security Key instead which is half the price and doesn't do PIV or OTP.

And also can't be kept in the side of a laptop without eventually breaking
the USB port.

Thanks for the advice but now I'll provide you with advice:

> That said, I politely appeal to Theo D. to revert this change because it
> doesn't make sense. Yes - I fully agree Yubikey tooling is dogshit - but
> it is what it is, and to be honest most people provision Yubikeys on other
> platforms where they provide GUI tools such as Mac OS. Once provisioned,
> the keys work fine.

You know the problem.  You know who can fix it.  This is their problem,
not ours.  Or, write a configuration driver.

But I am not going to invest a second into this, and over a number of years
noone else has -- and we done with cccccblddbkhgvtvjihbdcjdbtkgddnuigbievtbtcgr
and a tradeoff has been selected.