GTIN: 5060408462331. 0 interface. Our customers include 9 of the top 10 internet companies, 3 of the 5 leading financial and retail companies, and several of the largest. The Security Key NFC - Enterprise Edition includes a serial number for asset tracking, both accessible via software and laser marked on the back. This situation can be improved upon by enforcing a second authentication factor - a Yubikey. If you were a target. websites and apps) you want to protect with your YubiKey. (PKI) where authentication credentials can be stored in a YubiKey enhancing the security of the authentication. Yubico Authenticator is a software-based authenticator by Yubico for authenticating users of software applications. Both will function with any YubiKey that. For example 5. 3 and up can utilize longer responses to queries from OpenPGP, allowing more data to be sent per interaction and reduce the overall time for operations, especially in environments where the USB communication latency is the largest bottleneck. com at a retail price of $80 for the USB-A form-factor and $85 for the USB-C form-factor. 3. Option 3 - Certificate Management System (CMS) Portal. CHAPTER ONE INTRODUCTION TheYubiKeyManager(ykman)isacross-platformapplicationformanagingandconfiguringaYubiKeyviaagraphical userinterface(GUI)andaPython3. I just received my second YubiKey 5 NFC, it also has 5. “By integrating directly with the Yubico SDK, Allscripts is improving the multi-factor authentication (MFA) experience that is needed to comply. The YubiKey Manager has both a. Note: The YubiKey 5 FIPS Series with initial firmware release version 5. See this article for more info. This option is only valid for the 2. The YubiKey Bio Series, built primarily for desktops, offers secure passwordless and second factor logins, and is designed to offer strong biometric authentication options. Meets the most stringent hardware security requirements with fingerprint templates stored in the secure element on the key. In March, we published a blog called “ YubiKeys, passkeys and the future of modern authentication ” which took a look at the evolution of authentication from when we first. 2, this marks a major upgrade from three years ago when the original YubiKey FIPS Series was launched with firmware. Yubico said customers would receive new YubiKey FIPS Series keys with a corrected firmware version of 4. 0 and NFC interfaces. Note that certain keys, such as the Security Key by Yubico, do not have serial numbers. Note: Some software such as GPG can lock the CCID USB interface, preventing another software from accessing applications that use that mode. Trustworthy and easy-to-use, it's your key to a safer digital world. -S0605. The Yubikey itself contains non-upgradable firmware. Trustworthy and easy-to-use, it's your key to a safer digital world. It provides an easy way to perform the most common configuration tasks on a YubiKey, such as: Checking Firmware Version Launch the YubiKey Manager App and connect your YubiKey if it is not already connected. PIV: FIPS 140-2 with YubiKey 5 FIPS Series. 2). 75mm. Download and run YubiKey for Windows Hello from the Store. government. Yubikey FIPS vulnerability. 2. The YubiKey 5 series, image via Yubico. 3. This applet is not configurable and cannot be reset. , set a AES key) YubiKeys. The best security key of 2023 in full: (Image credit: Yubico) 1. PGP is not used for web authentication. 4. Get answers to commonly asked questions. Description. But bug and performance fixes are always welcome if you can't upgrade the firmware. com >. The step-kms-plugin—a plugin for step for working with external key management hardware and. FriendlyName -like "*YubiKey*"} | Select-Object -ExpandProperty FriendlyName. YubiHSM, YubiHSM 2, YubiKey 5 Series, YubiKey 4 Series, YubiKey FIPS Series, Security Key by Yubico Series, or previous generation YubiKey devices are not impacted. On Linux platforms you will need pcscd installed and running to be able to communicate with a YubiKey over the SmartCard interface. I just received my second YubiKey 5 NFC, it also has 5. The YubiKey Personalization package contains a library and command line tool used to personalize (i. Manage pin codes, configure FIDO2, OTP and PIV functionality, see firmware version and more. To update to 16. 0 and NFC interfaces. Learn more > Yubico announces general availability of next-generation Android and iOS SDKs. access, amend, and share your data. If you are interested in. It’s a robust, affordable “key to many locks” that stays with you as your technology and threats change. Company. The main benefit with your own server is that you are in full control over all AES keys programmed into the YubiKeys. Note that the tool will only read a single YubiKey at a time, so if you have multiple keys connected, it might not be evident which one the tool is identifying. 6. $22. The YubiKey 5 Series is a hardware based authentication solution that offers strong two-factor, multi-factor and passwordless authentication with support for multiple. YubiHSM Auth uses hardware to protect these long-lived credentials. 0 interface as well as an NFC interface. The YubiKey is a hardware authentication device manufactured by Yubico to protect access to computers, networks, and online services that supports one-time passwords (OTP), public-key cryptography, and authentication, and the Universal 2nd Factor (U2F) and FIDO2 protocols [1] developed by the FIDO Alliance. At the prompt, enter your device/iPhone passcode to continueWrite NDEF URI to YubiKey NEO, must be used with -1 or -2 -tXXX. 99. When we launched the YubiKey 5Ci on August 20, we also introduced a new firmware to the YubiKey 5 Series: version. YubiKey Manager can be installed independently of platform by using pip (or equivalent): pip install --user yubikey-manager. with a yubikey their firmware cannot be updated so the only way to get a newer firmware is to get a new key, do you have a set schedule of when you upgrade keys or do you use a key til it physically fails or breaks? would you upgrade before a failure if a firmware update would give you features you like? would you rather upgrade before a failure so you avoid. PGP has the following advantages: De. As of today, we're starting to ship the YubiKey 5 Series with firmware 5. The YubiKey is a hardware authentication device manufactured by Yubico to protect access to computers, networks, and online services that supports one-time passwords (OTP),. Launch ykman CLI, ( 64-bit)Find the right YubiKey. 3 FIPS 140-2 Security Level: 1 1. 3 added two that were actually quite a big deal to me but others probably cared nothing about: - support. Software that allows the Yubikey to communicate with other services. You can also use the tool to check the type and firmware of a YubiKey, or to perform batch programming of a large number of YubiKeys. OATH: FIPS 140-2 with YubiKey 5 FIPS Series. YubiKeys, the industry’s #1 security keys, work with hundreds of products, services, and applications. You may be prompted for a PIN when running pamu2fcfg. Open Yubico Authenticator for iOS. That being said, as a next step we would encourage you to check with Apple Support on this as well regarding this issue. FIDO. Download the yubico-piv-tool. Locate and double-click on YubiKey-Minidriver MSI Windows Installer. Works with any currently supported YubiKey. To find out if an application is compatible with the YubiKey C Bio - FIDO Edition, browse to the Works With YubiKey Catalog, and in YubiKey drop-down, select YubiKey Bio Series to only display services that are compatible with it. 9. YubiKeys are available worldwide on our web store and through authorized resellers. For more details, see the article on our Developer site, YubiKey and PIV . 3 or newer. We will introduce a new retail web sales. 1 firmware just released, roadblocks that prevented YubiHSM 2 products integration with more widely available libraries and operating systems have been removed. DEV. Keep your online accounts safe from hackers with the YubiKey. CHEATSHEETS. There is one “non-secure” USB interface controller and one secure crypto processor, which runs Java Card (JCOP 2. 2. 2, the YubiKey PIV management key can also be an AES key. Azure AD and YubiKey support for phishing-resistant authentication continues to grow day by day. YubiHSM Auth uses hardware to protect these long-lived credentials. 3. Note that several components included in the SDK depend on the YubiHSM library from the yubihsm-shell project. The issue weakens the strength of on-chip RSA key generation and affects some use cases for the Personal Identity Verification (PIV) smart card and OpenPGP functionality of the YubiKey 4 platform. The biggest change that would force you to go to a 5 would be using FIDO2 with resident credentials. Can I upgrade my firmware? What is the YubiKey's account limit? How do I use the YubiKey Manager & Yubico Authenticator? My YubiKey is not working, what should I do? My NFC is not working I want to learn more! Security protocols explained What is a YubiKey? Use the YubiKey Manager to configure FIDO2, OTP and PIV functionality on your YubiKey on Windows, macOS, and Linux operating systems. With the release of the YubiKey firmware version 5. FIDO U2F. To find compatible accounts and services, use the Works with YubiKey tool below. 3. x firmware line. YubiHSM Series Legacy Devices YubiKey 4 Series To identify the version of YubiKey or Security Key you have, use YubiKey Manager. Works on yubikey 5 nfc. use a password manager like. 4. YubiKey Manager (ykman) The YubiKey Manager is a tool for configuring all aspects of 5 Series YubiKeys and for determining the model of YubiKey and the firmware running on the YubiKey. The YubiKey 5C Nano uses a USB 2. The YubiKey Bio Series, built primarily for desktops, offers secure passwordless and second factor logins, and is designed to offer strong biometric authentication options. Remember to. After you do this then only someone with both the password and the Yubikey will be able to use the SSH key pair. YubiKey works out-of-the-box and has no client software or battery. If you have an older device and wish to get the latest firmware, you will need to purchase a separate. The YubiKey 4 & 5 has 15,260 bytes available for storing Certificate Chain Certificates (root and intermediate certificates). Works with any currently supported YubiKey. Using the YubiKey Manager GUI The YubiKey Manager’s (ykman’s) graphical user interface (GUI) is a quick, convenient way to find out what firmware your YubiKey has and/or to reset it - unless you prefer to use. 2 R1). 4 Support. The YubiKey. Note: Some software such as GPG can lock the CCID USB interface, preventing another. If you find that you can copy files to your YubiKey, it may be that you're using a counterfeit device, i. After inserting the YubiKey into a USB Port select Continue. 2 does not support OpenPGP. Instead of a code being texted to you, or generated by an app on your phone, you press a button on your YubiKey. Unfortunately, my YubiKey 5 NFC does have an older firmware (5. Usually, when using a HSM for a CA, we mean: the CA private key (usually RSA) is generated, stored and used within the HSM, and the HSM will commit honourable suicide rather than letting that key ever exit its entrails. 3. Some features depend on the firmware version of the Yubikey. Firmware cannot be updated on existing devices. The May 2021 Biden executive order urged all Federal as well as State and Local agencies, and any private sector organization serving these agencies to modernize cybersecurity with phishing-resistant multi-factor authentication (MFA). 0 interface. As of writing, it’s also the most popular physical key. USB-C. The secure session protocol is based on Secure Channel Protocol 3 (SCP03). Once we were notified of this issue by Infineon we quickly addressed it. 4. x. The PIV (Personal Identity Verification) standard specifies 25 slots. The YubiKey 5 NFC uses a USB 2. Hardware-backed strong two-factor authentication raises the bar for security while delivering the convenience of an. 4. multi-factor authentication. 😞. This can be used with GPG4Win for encryption and signing, as well as for SSH authentication. YubiHSM Auth is supported by YubiKey firmware version 5. 0 interface. It is currently not possible to upgrade YubiKey firmware. Note: The YubiKey 5 FIPS Series with initial firmware release version 5. 2 or 4. Yubico SCP03 Developer Guidance. Use YubiKey Manager to check your YubiKey's firmware version. 6 (or later) library and command line interface (CLI). Addressing the Issue in YubiKey Firmware. GPG4Win can act as a drop-in. Note: The YubiKey 5 FIPS Series with initial firmware release version 5. Firmware version: [your yubikey firmware version] Form factor: [description of your yubikey interface] Enabled USB interfaces: [list of what is enabled] Applications OTP Enabled FIDO U2F Enabled OpenPGP Enabled PIV Enabled OATH Enabled FIDO2 Enabled The important part for this, is to make sure that the "openpgp" "app" on your. The private key is protected by the hardware and software. 6b (released 2019-06-11)The YubiKey 5C has six distinct applications, which are all independent of each other and can be used simultaneously. FIDO: FIPS 140-2 with YubiKey 5 FIPS Series. The YubiKey also allowed for issuing multiple backups to each employee, including one YubiKey nano designed to sit inside the user’s laptop and one YubiKey designed for a keychain. Touch the gold contact on the YubiKey. The rest is protected by NDAs since the secure chip manufacturers don't like open sourcing their code (and by extension any code that runs on those. It isn't that sort of USB device. Provides library functionality for FIDO2, including communication with a device over USB or NFC. Use OATH with the YubiKey. Version 1. 3. The YubiKey 5 NFC uses a USB 2. Device type: YubiKey NEO Serial number: X Firmware version: 3. You can also use the tool to check the type and firmware of a YubiKey. If you have yubihsm-shell version 2. Secret ID is now always a random value. USB-C and lightning bolt. Interface. PGP has the following advantages: De facto standard in the Gnu/Linux world and for e-mail encryption. To find out if an application is compatible with the Security Key NFC, browse to the Works With YubiKey Catalog, and in YubiKey drop-down, select Security Key NFC to only display services that are compatible with it. While YubiKeys come in a number of different form-factors, each is built around the same core chipset and firmware, allowing a uniform experience regardless of the model used. The NEO has a set of card manager keys that allows you to delete/add/update the software “applets” running on the NEO, through the Global Platform interface. 4. Yubico’s YubiKey 5 NFC — which uses both a USB-A connector and wireless NFC — is the best key for logging into your online accounts. Specifically, the fix was not good for newer Yubikey firmware (like 5. YubiKey VerificationThe YubiKey 5 Series supports most modern and legacy authentication standards. YubiKey BIO supports biometric authentication (I presume with on-board fingerprint verification) to use the device's keys. FormFactor Standard YubiKey Value SecurityKeyValue(FW 5. "Most popular security keys, like the Yubikey, are closed sourced which limit their usefulness for hackers like myself. YubiKeyは複数の認証プロトコルをサポートしており、あらゆる技術スタックで(レガシーでも最新でも)動作します。. you can reset it if u really think someone is doing bad things with. YubiKey firmware 1. Interface. Infineon RSA Key Generation Issue - Customer Portal. The YubiKey is a set of multiprotocol authentication devices that "pairs well with all the new gadgets," she said. The first paragraph means YubiKey firmware is non-alterable. 2. Updated Pricing Strategy. 2130) GnuPG: 2. Introduction. The YubiKey 5C Nano FIPS has five distinct applications, which are all independent of each other and can be used simultaneously. You. 2) and can not do this. 4. 7. Primary Functions: Secure Static Passwords, Yubico OTP, OATH – HOTP (Event), OATH – TOTP (Time), Smart Card (PIV-Compatible), OpenPGP, FIDO U2F, FIDO2. This issue occurs during power-up of the YubiKey only. Download the Yubico Authenticator App. To find compatible accounts and services, use the Works with YubiKey tool below. All of the applications are available through both interfaces. Yubico Authenticator App for Desktop and Mobile | Yubico. YubiKeyをタップすれは検証. 1 and later enables you to enroll and manage fingerprints on all supported operating systems. Select Add Security Keys . Add your credential to the YubiKey with touch or NFC-enabled tap. 4 (inclusive) since these chips are vulnerable to CVE-2017-15631. Resolution for SonicOS 7. In KeePass' dialog for specifying/changing the master key (displayed when. e. YubiHSM Auth is a YubiKey CCID application that stores the long-lived credentials used to establish secure sessions with a YubiHSM 2. The first YubiKeys that implemented PIV only supported five of the slots. Write NDEF text to YubiKey NEO, must be used with -1 or -2 -mMODE Set the USB device configuration of the YubiKey. Follow the. Support for OpenPGP was added in firmware version 5. Unfortunately your situation is as described above. It will show you the model, firmware version, and serial number of your YubiKey. Registering a YubiKey with Bitwarden just takes a few clicks in the Two-step Login tab under Security in Account Settings. Learn more >YubiHSM Auth overview. Multiple form factors with support for USB-A, USB-C, NFC and Lightning. 5 and earlier firmware. The YubiKey FIPS (4 Series) are marked “FIPS” and will have firmware version 4. If I'm going to be going through the entire setup process with a primary and backup key, working through everything with this new backup mechanism in place sounds like it'd be pretty efficient. Yubikey. The small YubiKey 4 Nano is priced at $50, and the YubiKey 4, the larger keychain version, is $40. Interface. 4. This article covers configuration steps for SonicOS firewalls to work with YubiKey TOTP. Has ProducId 0x110, 0x111 or 0x112 depending on mode (see the notes about -m and device_config). 4. FIDO2 authenticators YubiKey 5 Series. ) Yubikey: Yubico Yubikey 5 NFC (Firmware version: 5. Interface. The YubiKey 5C FIPS has five distinct applications, which are all independent of each other and can be used simultaneously. co/yubikey-firmwa re-update-5-4. Outdated Firmware With more recent hardware and operating systems, outdated YubiKey firmware can cause compatibility problems. They will issue you a replacement if you have a device that is relatively current and has a security flaw discovered. 4. This new firmware release will enable easier integration with Credential Management System (CMS) solutions, secure remote. The YubiKey FIPS (4 Series) are hardware authentication devices manufactured by Yubico which support one-time passwords, public-key encryption and authentication, and the Universal 2nd Factor (U2F) protocols developed by the FIDO Alliance, with Yubico as a primary contributor and thought leader. Stops account takeovers. It's small—a little shorter than a house key. The YubiKey 5 Series supports most modern and legacy authentication standards. The new Nitrokey 3 is the best Nitrokey we have ever developed. x. Also I am currently unaware wether there's a variant of CSPN certified. The YubiKey Bio Series is available for purchase on yubico. Simply plug in via USB-A or tap on your. 2. 4. That was all time wasted that you could. 4. " In the security advisory for the issue,. If you have a 20-character alphanumeric PIN, that chance is 8 in 200 trillion. With the YubiKey software, you can enable or disable features on your YubiKey, like PIV, OATH or OpenPGP. Run: pamu2fcfg > ~/. Copyable passkeys can be synced across smartphones, tablets, and laptops/desktops and are primarily meant for. Getting a biometric security key right. not a genuine YubiKey. Two types of discoverable FIDO credentials enable passwordless authentication; copyable or hardware bound. The YubiKey 4 and YubiKey NEO have five separate. 2. If you're looking for setup instructions for your. NFC Data Exchange Format (NDEF) messages are sent to the YubiKey via USB or NFC to update NDEF records. The functions that it executes are extremely limited, which means the target attack space is extremely limited. ECC keys are supported on YubiKey 5 devices with firmware version 5. Browse the YubiKey compatibility list below! Explore the Works With YubiKey Catalog to find a wide range of. ) Firmware version: 0x05: The Major. 4 have reduced randomness in generated keys because, according to Yubico, "the buffer holding the value contains some predictable content making the value less random than intended. e. 4. YubiKey 5 Series. FIPS is a security certification that meets strict security standards. The YubiKey 4 has five distinct applications, which are all independent of each other and can be used simultaneously. The quickest and most convenient way to determine your device’s firmware version is to use the YubiKey Manager tool (ykman), a lightweight software package installable on any OS. 28 -> 2. Note: Some software such as GPG can lock the CCID USB interface, preventing another software from accessing applications that use that mode. Add your credential to the YubiKey with touch or NFC-enabled tap. The access code is not checked when updating NFC specific components. 4. In order to protect your KeePass database using a YubiKey, follow these steps: Start a text editor (like Notepad). So it's essentially a biometric-protected private key. Unfortunately, Yubikey firmware is NOT upgradable. CLA INS P1 P2 Lc Data; 0x00: 0x01: 0x10: 0x00 (absent) (absent) Response APDU info. Convenient and portable: The YubiKey 5C fits easily on your keychain, making it convenient to carry and use wherever you go, ensuring secure access to your accounts at all times. Each Security Key must be registered individually. 0. アプリを開いたりコードを入力したりするためにスマートフォンを手に取る必要はありません。. YubiHSM Auth uses hardware to protect these. Authenticators with the same capabilities and firmware, such as the YubiKey 5 series devices without NFC, can share the same. If you confirm OTP is enabled, either through the YubiKey NEO Manager or Devices and Printers, you may need to run the Personalization Tool GUI as Administrator (or. Total: AUD $ 120 . For more details, see the article on our Developer site, YubiKey and PIV . A single YubiKey works across multiple shared devices including desktops, laptops, mobile, tablets, and notebooks, enabling users to utilize the same key as they navigate between devices, and helping you deploy phishing-resistant MFA at scale. For basics, this hardware key can store up to 4096-bit RSA keys and up to. The security issue was found on June 6, 2017 and affected TPMs in millions of computers, and multiple smart card and security token vendors. In addition, one ECDSA key per online service can be. If you are, note that this is your YubiKey's FIDO2 PIN you need to enter. COMBO DEALS: Buy Together and SAVE! Save even more by creating your own combo deal with any of the items below and the Yubico Yubikey 5 Nano USB-A Two Factor Security Key. 5. All applications are available over this interface. 4. All NFC interfaces are turned on in the. It offers NFC, USB-C and USB-A Mini (optional) for the first time. I received today a Yubikey 5C NFC from Amazon. I have 2 Yubikey 5 NFC keys that I mainly use for FIDO2 authentication. To prevent attacks on the YubiKey which might compromise its security, the YubiKey does not permit its firmware to be accessed or altered. The YubiKey is a device that makes two-factor authentication as simple as possible. The Nitrokey 3 combines the features of previous Nitrokey models: FIDO2, one-time passwords, OpenPGP smart card, Curve25519, password manager, Common Criteria EAL 6+ certified secure element,. The replacement is free and you don't need to turn in your old device. This is the same as the backup and recovery offered by commercial HSMs or the key domains offered by SC-HSM 4K. 3 or higher. This is the recommended method for registering a YubiKey as an OATH-TOTP token. Several data objects (DOs) with variable length have had their maximum. 3. Yubikeys are a type of security key manufactured by Yubico. And the reason for this limitation is clearly for security reasons since you can expect your key to always running the software released by Yubico without any possibility to install a custom. 4. 3 firmware for the YubiKey, we have decided to add a “dormant” YubiCloud config to the second slot. Lr Data SW1 SW1; 0x04:. 5. The Security Key NFC - Enterprise Edition provides the FIDO2 application as well as the U2F application, and can communicate using near-field communication (NFC), allowing for greater flexibility. As an example, Google's instructions for using YubiKeys with Android can be found here. Matt Davey COO, 1Password. Insert the YubiKey into the USB port if it is not already plugged in. 6(orlater. 2 firmware. 12, and Linux operating systems. Deploying the YubiKey 5 FIPS Series. Only the firmware that runs on the YubiKey itself is closed source even though all the protocols are fully standardized and documented (so making your own YubiKey like firmware is fairly trivial). For YubiKey version 5: $ ykman info Device type: YubiKey 5 NFC Serial number: XXXXXXXXX Firmware version: 5. So if I remove my YubiKey or lose the YubiKey. To set and manage the PIN, enroll fingerprints and manage stored credentials, Step 1: Launch the Yubico Authenticator, and select the YubiKey menu option. Right, the YubiKey firmware destroys* the keys after 8 unsuccessful PIN attempts in a row. The Yubico PIV tool is used for interacting with the Privilege and Identification Card (PIV) application on a YubiKey, which you'll need to do to determine if your YubiKey is locked. PGP is not used for web authentication. See the manpage for details. The YubiKey NEO has USB 2. This applies to: Pre-built packages from platform package managers. 27" in the macOS System Report). Run: sudo add-apt-repository ppa:yubico/stable && sudo apt-get update. Upgraded firmware benefits specific business scenarios — Based on firmware 5. ‘ykman oath accounts list’ for oath-totp accounts. 0 – 5. In case you mess anything up, you would need a backup of your LUKS header. x and later Long press (slot 2): YubiKey firmware 2. Get the current connection mode of the YubiKey, or set it to MODE. OTP: FIPS 140-2 with YubiKey 5 FIPS Series. It is currently not possible to upgrade YubiKey firmware. ) Yubikey: Yubico Yubikey 5 NFC (Firmware version: 5. The YubiKey Manager has both a. Customers rangehave a VIP YubiKey with a firmware version of 2. Note: Some software such as GPG can lock the CCID USB interface, preventing another software from accessing applications that use that mode. The Ubuntu community has created many apps with YubiKey support to enable strong authentication and encryption. 4. It determines what features the device has. The YubiKey will wait for the user to press the key (within 15 seconds) before answering the challenge. 7!Yubico is the leading provider of hardware authentication security keys — devices which protect logins to online accounts from phishing, man-in-the-middle, and other threats of account takeover. YubiHSM Auth is supported by YubiKey firmware version 5. 4. This way, one key. Convenient and portable: The YubiKey 5 NFC fits easily on your keychain, making it convenient to carry and use wherever you go, ensuring secure access to your accounts at all times. Connector: USB-A Dimensions: 18mm x 45mm x 3. The YubiKey 5 Series supports most modern and legacy authentication standards. YubiKey Secure Channel Initialize Update Flow. 2. 2, 4. Upgraded firmware benefits specific business scenarios — Based on firmware 5. If you wanted to use the YubiKey with a YubiCloud service (such as LastPass) you would need to add a YubiCloud credential to the YubiKey VIP. # For example, set ssh key path (-f) and comment (-C) An issue exists in the YubiKey FIPS Series devices with firmware version 4.