Are there any FIDO security keys that explicitly support backing up and restoring their master secrets? I would love to move from Username + Password + TOTP but my current workflow requires that I am able to regain access to my digital accounts using nothing but a few page paper backup including core service passwords & exported TOTP secrets.
> Are there any FIDO security keys that explicitly support backing up and restoring their master secrets? Why would you need that ? On most services that I use that support FIDO, you can register as many keys as you like. Seems to me that is a much more secure option than to provide a potentially exploitable option of allowing key extraction.
Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
251–260 of 525 posts
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#252The problem with any key based auth or biometric auth is a user can be compelled by LEO to hand over private keys or open a biometric lock. Passwords are protected by the 5th amendment.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#253The problem with any key based auth or biometric auth is a user can be compelled by LEO to hand over private keys or open a biometric lock. Passwords are protected by the 5th amendment.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#254Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#255Earlier quoted context omitted.
Can you share any more information about that? Is this identifier shared as part of the FIDO2/U2F spec?
I think they're referring to attestation ( https://fidoalliance.org/fido-technotes-the-truth-about-atte... .), which requires that attestation certificates be shared with a minimum of 100,000 other devices in order to ensure they're not unique IDs. Maybe the parent misread the spec as saying a _maximum_ of 100,000? Or something?
Also, the Alliance could decide to blacklist a manufacturer just because they haven't implemented some new policy (like requiring a DNA scan of the user) so you better make sure that you buy a device from one of the "too big to fail" providers.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#256Are there any FIDO security keys that explicitly support backing up and restoring their master secrets? I would love to move from Username + Password + TOTP but my current workflow requires that I am able to regain access to my digital accounts using nothing but a few page paper backup including core service passwords & exported TOTP secrets.
For users with a greater threat model (worry about enclave being hacked), they can use physical FIDO keys.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#257Earlier quoted context omitted.
I haven't run into any like that, but I'm with you -- if I could only store one webauthn key, I wouldn't use it at all. Too risky.
I believe AWS root accounts don't support more than one key to be added.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#258Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#259The problem with any key based auth or biometric auth is a user can be compelled by LEO to hand over private keys or open a biometric lock. Passwords are protected by the 5th amendment.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#260The problem with any key based auth or biometric auth is a user can be compelled by LEO to hand over private keys or open a biometric lock. Passwords are protected by the 5th amendment.