Earlier quoted context omitted.
Yes. You must have at least two keys registered. However it’s worth noting that most services do not offer priority. Meaning you can use either one. I think it makes sense to designate back up keys and only to be used when user reports lost/stolen primary key.
But what is the story there? You have a backup key, hopefully stored "off site", now you want to enroll in another website. You have to get that backup key before you do that? Or bookkeep which sites you have on the backup key and which you don't?
That's not how 2FA works
191–200 of 269 posts
Re: That's not how 2FA works
#192The linked article is correct, but uncharitable. It correctly states the behavior of two-factor auth systems but incorrectly understands their value . Yes, 2FA won't protect you from being phished by a site if you aren't careful. 2FA absolutely will protect you from a phishing site using the password it stole. So no, when someone says "Use 2FA if you might be phished" you shouldn't be replying "That's not how 2FA wor…
The attacker could proxy the 2FA request from the real site using the password you enter and therefore you wouldn't be protected.
Re: That's not how 2FA works
#193Earlier quoted context omitted.
Some other responders have given you the answer as it currently exists. They are all either inconvenient, weaken security, or both. For that reason, I would only suggest using a security key for a small number of critical services, where it's worth the extra effort to deal with the backup mechanisms. However, a good solution for this issue is finally in the works: https://www.yubico.com/blog/yubico-proposes-webauthn-…
Having two keys, one of which you keep in a secure place, seems pretty simple and intuitive to me.
Re: That's not how 2FA works
#194Earlier quoted context omitted.
The attacker could proxy the 2FA request from the real site using the password you enter and therefore you wouldn't be protected.
Right, they could have access to your account, but not full access. A good website will ask for 2FA again if a user tries to do something destructive (like change password, email, or disable 2FA). They wouldn’t be able to do those things.
Re: That's not how 2FA works
#195Most sites that support U2F support enrolling multiple tokens, so just have one in each machine.
Theft of a machine still needs your password to access the accounts, so it's not "keys to the kingdom" as the article suggests.
I feel that this article is... wrong.
Re: That's not how 2FA works
#196They author makes a few good points, but I find the author's critique of Yubikey weak: >Cost. The average YubiKey is £50... If that's too expensive for ensuring your internet security, then either you underestimate the risks, or undervalue your information. If a Yubikey cost 10 times more it would still be a bargain. >Usability. Buy a device, register it, install the app, configure it, find the setting in the website…
Just because it’s a website problem , it doesn’t stop being a problem. Usability is important if you want adoption outside of the HN crowd.
Re: That's not how 2FA works
#197Earlier quoted context omitted.
If my Yubikey gets stolen, how do I log in into my accounts? Serious question; never understood how that works.
I have a backup U2F device. You can register multiple with any account. If I somehow manage to lose both, I assume I’ll have to talk to a customer support rep or something.
Re: That's not how 2FA works
#198Earlier quoted context omitted.
> may I suggest spending a couple of days volunteering for a local Victim Support charity. Please try being less condescending. Losing the keys, due to whatever reason, means losing one factor. If the user loses the key, the "mugger" still needs to get the users' passwords. 2FA = something you know + something you own. Having one factor compromised should not compromise your accounts if the service you are using is c…
What’s the second factor with yubikey? The site seems to say it’s passwordless.
Re: That's not how 2FA works
#199Earlier quoted context omitted.
I have helped literally hundreds of people setup Yubikeys across several companies. Your take is just not my experience at all. Tapping a blinking light it is much easier than fussing with a 2FA app and works when someone's phone is dead. Yubikeys in particular are near indestructible. They even work after you soak them in acetone overnight and melt the plastic off. I tried. When it says "plug in your device" you plu…
If my Yubikey gets stolen, how do I log in into my accounts? Serious question; never understood how that works.
Re: That's not how 2FA works
#200The author recommends BitWarden, but it seems like it's run by one guy. How do I know he doesn't go away? Get hit by a bus?