Do you really need a CTAP proxy?

Without any CTAP proxy implementation the Yubikey works if you just pass it to the qube you’re trying to login from through the USB tray icon

From the guide:

The Qubes CTAP Proxy is a secure proxy intended to make use of CTAP two-factor authentication devices with web browsers without exposing the browser to the full USB stack, not unlike the USB keyboard and mouse proxies implemented in Qubes.

I’m confused about the downsides if I don’t implement a CTAP proxy. Can someone provide some clarity about the potential risks without CTAP implementation?

Also, I understand that implementing per-cube key access is supposed to prevent against stuff similar to the WebUSB bypass, but if you’re going to have a qube to specifically only login to 1 website with a firewall that also limits outgoing connections to said website, how insecure would it be to ignore CTAP implementation?

Also would doing this even do anything: Shutting down all other qubes besides the one where you’re trying to login(excluding the necessary service qubes), or is this pointless because an intruder can’t move to other qubes in addition to only being allowed to attach the Yubikey(or any other USB device) to 1 qube at a time?

1 Like