{"id":24,"date":"2017-07-20T00:00:00","date_gmt":"2017-07-20T07:00:00","guid":{"rendered":"https:\/\/github.test\/2017-07-20-soft-u2f\/"},"modified":"2017-07-20T00:00:00","modified_gmt":"2017-07-20T07:00:00","slug":"soft-u2f","status":"publish","type":"post","link":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/","title":{"rendered":"Soft U2F"},"content":{"rendered":"<p>In an effort to increase the adoption of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Universal_2nd_Factor\">FIDO U2F<\/a> second factor authentication, we&#8217;re releasing <a href=\"http:\/\/github.com\/github\/SoftU2F\">Soft U2F<\/a>: a software-based U2F authenticator for macOS.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" src=\"https:\/\/i0.wp.com\/user-images.githubusercontent.com\/1144197\/28530169-198b3ca2-7050-11e7-952b-21358b0fa0b0.gif?ssl=1\" alt=\"Soft U2F Demo\"><\/p>\n<p>We&#8217;ve long been interested in promoting better user security through two-factor authentication on GitHub.com. Initially, we <a href=\"https:\/\/github.com\/blog\/1614-two-factor-authentication\">added support<\/a> for <a href=\"https:\/\/en.wikipedia.org\/wiki\/Time-based_One-time_Password_Algorithm\">TOTP<\/a>-based 2FA. A few years later, we <a href=\"https:\/\/github.com\/blog\/2071-github-supports-universal-2nd-factor-authentication\">added support<\/a> for FIDO U2F. U2F provides a better user experience, while overcoming several security shortcomings of TOTP. Unfortunately, U2F adoption has been low, presumably due to the need to purchase a physical device.<\/p>\n<p>In order to lower the barrier to using U2F, we&#8217;ve developed a software-based U2F authenticator for macOS: <a href=\"http:\/\/github.com\/github\/SoftU2F\">Soft U2F<\/a>. Authenticators are normally USB devices that communicate over the HID protocol. By emulating a HID device, Soft U2F is able to communicate with your U2F-enabled browser, and by extension, any websites implementing U2F.<\/p>\n<p>The Soft U2F installer can be downloaded <a href=\"https:\/\/github.com\/github\/SoftU2F\/releases\">here<\/a> and the source code can be found <a href=\"http:\/\/github.com\/github\/SoftU2F\">here<\/a>. Contributions to the project are welcome.<\/p>\n<h3 id=\"security-considerations-of-hardware-vs-software-key-storage\"><a class=\"heading-link\" href=\"#security-considerations-of-hardware-vs-software-key-storage\">Security considerations of hardware vs. software key storage<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h3>\n<p>A USB authenticator stores key material in hardware, whereas Soft U2F stores its keys in the macOS Keychain. There is an argument to be made that it is more secure to store keys in hardware since malware running on your computer can access the contents of your Keychain but cannot export the contents of a hardware authenticator. On the other hand, malware can also access your browser&#8217;s cookies and has full access to all authenticated website sessions, regardless of where U2F keys are stored.<\/p>\n<p>In the case of malware installed on your computer, one meaningful difference between hardware and software key storage for U2F is the duration of the compromise. With hardware key storage, you are only compromised while the malware is running on your computer. With software key storage, you could continue to be compromised, even after the malware has been removed.<\/p>\n<p>Some people may decide the attack scenario above is worth the usability tradeoff of hardware key storage. But, for many, the security of software-based U2F is sufficient and helps to mitigate against many common attacks such as password dumps, brute force attacks, and phishing related exploits.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In an effort to increase the adoption of FIDO U2F second factor authentication, we&#8217;re releasing Soft U2F: a software-based U2F authenticator for macOS. We&#8217;ve long been interested in promoting better&hellip;<\/p>\n","protected":false},"author":1353,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_gh_post_show_toc":"","_gh_post_is_no_robots":"","_gh_post_is_featured":"","_gh_post_is_excluded":"","_gh_post_is_unlisted":"","_gh_post_related_link_1":"","_gh_post_related_link_2":"","_gh_post_related_link_3":"","_gh_post_sq_img":"","_gh_post_sq_img_id":"","_gh_post_cta_title":"","_gh_post_cta_text":"","_gh_post_cta_link":"","_gh_post_cta_button":"","_gh_post_recirc_hide":"","_gh_post_recirc_col_1":"","_gh_post_recirc_col_2":"","_gh_post_recirc_col_3":"","_gh_post_recirc_col_4":"","_featured_video":"","_gh_post_additional_query_params":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"{title}\n\n{excerpt}\n\n{url}","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false,"_links_to":"","_links_to_target":""},"categories":[72,3310],"tags":[],"coauthors":[],"class_list":["post-24","post","type-post","status-publish","format-standard","hentry","category-engineering","category-platform-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Soft U2F - The GitHub Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Soft U2F\" \/>\n<meta property=\"og:description\" content=\"In an effort to increase the adoption of FIDO U2F second factor authentication, we&#8217;re releasing Soft U2F: a software-based U2F authenticator for macOS. We&#8217;ve long been interested in promoting better&hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/\" \/>\n<meta property=\"og:site_name\" content=\"The GitHub Blog\" \/>\n<meta property=\"article:published_time\" content=\"2017-07-20T07:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/user-images.githubusercontent.com\/1144197\/28530169-198b3ca2-7050-11e7-952b-21358b0fa0b0.gif\" \/>\n<meta name=\"author\" content=\"Ben Toews\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Toews\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/soft-u2f\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/soft-u2f\\\/\"},\"author\":{\"name\":\"Ben Toews\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/bca579121df32a2fb58ba464dd729937\"},\"headline\":\"Soft U2F\",\"datePublished\":\"2017-07-20T07:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/soft-u2f\\\/\"},\"wordCount\":379,\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/soft-u2f\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/user-images.githubusercontent.com\\\/1144197\\\/28530169-198b3ca2-7050-11e7-952b-21358b0fa0b0.gif\",\"articleSection\":[\"Engineering\",\"Platform security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/soft-u2f\\\/\",\"url\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/soft-u2f\\\/\",\"name\":\"Soft U2F - The GitHub Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/soft-u2f\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/soft-u2f\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/user-images.githubusercontent.com\\\/1144197\\\/28530169-198b3ca2-7050-11e7-952b-21358b0fa0b0.gif\",\"datePublished\":\"2017-07-20T07:00:00+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/bca579121df32a2fb58ba464dd729937\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/soft-u2f\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/soft-u2f\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/soft-u2f\\\/#primaryimage\",\"url\":\"https:\\\/\\\/user-images.githubusercontent.com\\\/1144197\\\/28530169-198b3ca2-7050-11e7-952b-21358b0fa0b0.gif\",\"contentUrl\":\"https:\\\/\\\/user-images.githubusercontent.com\\\/1144197\\\/28530169-198b3ca2-7050-11e7-952b-21358b0fa0b0.gif\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/soft-u2f\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/github.blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Engineering\",\"item\":\"https:\\\/\\\/github.blog\\\/engineering\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Platform security\",\"item\":\"https:\\\/\\\/github.blog\\\/engineering\\\/platform-security\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Soft U2F\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/github.blog\\\/#website\",\"url\":\"https:\\\/\\\/github.blog\\\/\",\"name\":\"The GitHub Blog\",\"description\":\"Updates, ideas, and inspiration from GitHub to help developers build and design software.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/github.blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/bca579121df32a2fb58ba464dd729937\",\"name\":\"Ben Toews\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fff3423c5eb9cf0ee9641d6bd6fecf37c280b26e32488ab01d680c182ee56114?s=96&d=mm&r=gacd7ecc342b2835c89851ffbfe836f22\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fff3423c5eb9cf0ee9641d6bd6fecf37c280b26e32488ab01d680c182ee56114?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fff3423c5eb9cf0ee9641d6bd6fecf37c280b26e32488ab01d680c182ee56114?s=96&d=mm&r=g\",\"caption\":\"Ben Toews\"},\"url\":\"https:\\\/\\\/github.blog\\\/author\\\/mastahyeti\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Soft U2F - The GitHub Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/","og_locale":"en_US","og_type":"article","og_title":"Soft U2F","og_description":"In an effort to increase the adoption of FIDO U2F second factor authentication, we&#8217;re releasing Soft U2F: a software-based U2F authenticator for macOS. We&#8217;ve long been interested in promoting better&hellip;","og_url":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/","og_site_name":"The GitHub Blog","article_published_time":"2017-07-20T07:00:00+00:00","og_image":[{"url":"https:\/\/user-images.githubusercontent.com\/1144197\/28530169-198b3ca2-7050-11e7-952b-21358b0fa0b0.gif","type":"","width":"","height":""}],"author":"Ben Toews","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ben Toews","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/#article","isPartOf":{"@id":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/"},"author":{"name":"Ben Toews","@id":"https:\/\/github.blog\/#\/schema\/person\/bca579121df32a2fb58ba464dd729937"},"headline":"Soft U2F","datePublished":"2017-07-20T07:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/"},"wordCount":379,"image":{"@id":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/#primaryimage"},"thumbnailUrl":"https:\/\/user-images.githubusercontent.com\/1144197\/28530169-198b3ca2-7050-11e7-952b-21358b0fa0b0.gif","articleSection":["Engineering","Platform security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/","url":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/","name":"Soft U2F - The GitHub Blog","isPartOf":{"@id":"https:\/\/github.blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/#primaryimage"},"image":{"@id":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/#primaryimage"},"thumbnailUrl":"https:\/\/user-images.githubusercontent.com\/1144197\/28530169-198b3ca2-7050-11e7-952b-21358b0fa0b0.gif","datePublished":"2017-07-20T07:00:00+00:00","author":{"@id":"https:\/\/github.blog\/#\/schema\/person\/bca579121df32a2fb58ba464dd729937"},"breadcrumb":{"@id":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/#primaryimage","url":"https:\/\/user-images.githubusercontent.com\/1144197\/28530169-198b3ca2-7050-11e7-952b-21358b0fa0b0.gif","contentUrl":"https:\/\/user-images.githubusercontent.com\/1144197\/28530169-198b3ca2-7050-11e7-952b-21358b0fa0b0.gif"},{"@type":"BreadcrumbList","@id":"https:\/\/github.blog\/engineering\/platform-security\/soft-u2f\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/github.blog\/"},{"@type":"ListItem","position":2,"name":"Engineering","item":"https:\/\/github.blog\/engineering\/"},{"@type":"ListItem","position":3,"name":"Platform security","item":"https:\/\/github.blog\/engineering\/platform-security\/"},{"@type":"ListItem","position":4,"name":"Soft U2F"}]},{"@type":"WebSite","@id":"https:\/\/github.blog\/#website","url":"https:\/\/github.blog\/","name":"The GitHub Blog","description":"Updates, ideas, and inspiration from GitHub to help developers build and design software.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/github.blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/github.blog\/#\/schema\/person\/bca579121df32a2fb58ba464dd729937","name":"Ben Toews","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/fff3423c5eb9cf0ee9641d6bd6fecf37c280b26e32488ab01d680c182ee56114?s=96&d=mm&r=gacd7ecc342b2835c89851ffbfe836f22","url":"https:\/\/secure.gravatar.com\/avatar\/fff3423c5eb9cf0ee9641d6bd6fecf37c280b26e32488ab01d680c182ee56114?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fff3423c5eb9cf0ee9641d6bd6fecf37c280b26e32488ab01d680c182ee56114?s=96&d=mm&r=g","caption":"Ben Toews"},"url":"https:\/\/github.blog\/author\/mastahyeti\/"}]}},"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/pamS32-o","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/24","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/users\/1353"}],"replies":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/comments?post=24"}],"version-history":[{"count":0,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/24\/revisions"}],"wp:attachment":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media?parent=24"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/categories?post=24"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/tags?post=24"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/coauthors?post=24"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}