Email or username:

Password:

Forgot your password?
Benno

“You must rotate your credentials every 60 days.”

*takes USB-C YubiKey out of slot*
*turns it upside down*
*plugs it back in*

29 comments
Bai Shen

@benno I'm reminded of the fact that USB C is directional so you could have a drive return different data depending on the orientation.

Peter

@valentinegb @baishen hackaday.com/2021/03/22/cursed is a fun trick.

>

although the USB-C plug has only a single pair of data lines (D+/-) for USB 2.0 connectivity, the receptor duplicates these on either side of its pins, leading out two pairs of D+/- lines. Normally you would connect the matching lines in these pairs together to ensure consistent behavior no matter the plug orientation, but you don’t have to.

Manawyrm | Sarah

@stibbons @valentinegb @baishen It's not a bug, it's a feature! You could build a USB flash drive that returns different data depending on orientation and protocol/speed (2.0/3.0) 😹

Damien (TIG BUSINESS)

@benno tried with USB-A key, now neither key nor port work, please advise

Trezzer (aka Helvedeshunden)

@aeduna @benno USB-A is more complicated to deal with. You'll need a full rotation. Please upgrade to a newer port release to do less manual work.

Chris

@aeduna @benno I actually own a travel charger for my Apple Watch that can be plugged in in either way. And yes, it’s USB A

Alex R :heart_progress:

@aeduna @benno for USB-A, simply rotate a full 360° half as often

JP

@benno new feature. The original yubikey didn’t have that.

Nathan :verified_OldBay:

@benno "Error: You have used that credential within the past six (6) rotation cycles. Please try again."

Reid D. M.

@benno @petrillic I wish I could respond with this to our password rotation policy

Stephen

@benno "Ticket closed: no response from user in 7 days."

Ellie

@benno I think they mean to change usernames.

0x10f

@benno "Please rotate your password by 180 degrees every 60 days. The password may only include the following characters: 0, 6, 8, 9, H, I, N, O, S, X, Z, b, d, l, n, o, p, q, s, u, x, z."

Matze

@benno But what if you’re not allowed to use one of the last 10 used credentials? 🫠

Steve Williams

@benno @mwl Snatch the pebble, security Ninja 🙏🏻

jwelzel

@benno please don‘t try this with an USB-A YubiKey.

fujiyamasamoyed 🐻‍❄️🌸🇨🇦

@benno turn over to side be and insert to F%$&ing box XD different time, same means of storage X3

Rox

@benno my password is now ᄅɹǝʇunɥ

Go Up