Earlier quoted context omitted.
My college uses Duo and it has no such restriction, if you tried this recently and couldn't add more than 1, it is probably set by LastPass/1Password.
Duo Free used to have a restriction of one device, but it seems for U2F they now require one of their paid plans: https://duo.com/product/trusted-users/two-factor-authenticat...
Support for U2F security keys
131–140 of 164 posts
Re: Support for U2F security keys
#132Earlier quoted context omitted.
I'm selling water bottles at $100/gallon. Considering water is literally essential to life, how many can I get you?
You must have had better ones than _that_, when you were thinking up a witty reply. I hope that wasn't you bringing your best.
Re: Support for U2F security keys
#133only tangential, but I've wanted to carry my Yubikey on my keyring, but have always been nervous about making it unreadable by sullying the contacts. Should I be concerned about this? Where do you all carry them?
Re: Support for U2F security keys
#134Re: Support for U2F security keys
#135Earlier quoted context omitted.
The way $dayjob makes this work is to issue a nano security key for each computer, and then a bluetooth security key for the iPhone (Android phones can use both NFC and Bluetooth security keys, but iPhones can only use Bluetooth security keys). It's cumbersome, but less so than when we were plugging and unplugging our one hardware USB-A OTP token into everything (and using a desktop web browser to generate OTPs for t…
What happens if your house burns down with everything in it? You’d then have to contact support to let you bypass 2FA, but if that’s possible then the 2FA protection is weak, prone to social hacking.
Re: Support for U2F security keys
#136Earlier quoted context omitted.
What happens if your house burns down with everything in it? You’d then have to contact support to let you bypass 2FA, but if that’s possible then the 2FA protection is weak, prone to social hacking.
"if your house burns down with everything in it, you'd have to call somebody" seems like a fairly ridiculous concern.
Re: Support for U2F security keys
#137Earlier quoted context omitted.
Well, yes, that is exactly what I'm talking about. The biggest advantage of a physical second factor is that I can see if it has been stolen: I either have it with me, or I don't. By using multiple keys, you are effectively removing that advantage: someone could have one of your devices (e.g. your laptop while you're out for lunch) and would be able to make use of your second factor without you knowing.
Well if your primary concern is a local threat - which it absolutely is not for the vast majority of people - then you just have to be more careful with your keys. If you suspect someone might be actively trying to break in to your home, you wouldn’t leave your keys on your desk while you went to lunch.
Re: Support for U2F security keys
#138Earlier quoted context omitted.
Autofill of a password manager is a working countermeasure against phishing too: If autofill does not work there is something wrong and you should look closer...
I can't find a source, but my recollection is that Google developed U2F because autofill didn't work reliably enough, so many users would just paste the password manually anyway.
Humans are bad at giving up. If there seems to be a way forward for the original plan they will press on, regardless of all indications that this now a bad idea. In fact Google had a security override in Chrome for years that was literally typing the sequence "badidea" in recognition of this. It's not specific to computer security, it happens in incident management, there's a seminal example from years back where a train breaks down, and the incident manager sees that step 1 of the response is to send a recovery train to the location, and literally _hours_ later, with passengers stranded and desperate - that manager was still wrestling with how to get the recovery train to the location so they could proceed to step 2, rather than realising that problems with the recovery train meant they needed to _abandon the entire plan and re-assess_ because humans are not good at that.
Re: Support for U2F security keys
#139I have long debated getting a Yubikey but have held off because I don't want to have to carry around several dongles at all times to be able to send an email. Surely other people are in the situation of: - iPhone, iPad - Macbook with only USB-C ports - Windows/Linux workstation with only USB-A ports Is there currently a non-cumbersome solution that will work on all of these?
The way $dayjob makes this work is to issue a nano security key for each computer, and then a bluetooth security key for the iPhone (Android phones can use both NFC and Bluetooth security keys, but iPhones can only use Bluetooth security keys). It's cumbersome, but less so than when we were plugging and unplugging our one hardware USB-A OTP token into everything (and using a desktop web browser to generate OTPs for t…
Re: Support for U2F security keys
#140Earlier quoted context omitted.
How do you manage keeping all the keys "synced" in terms of which services they are registered with. I keep keys in separate locations for safety, but that makes adding all keys to a new account a big pain. This hasn't been a big problem yet because there are so few services that support the keys, but I wonder how people would manage it if it became widespread.
It's a pain, I don't have a good answer. What I'm going to do personally is only use U2F on my most secure services (email, 1Password itself, GitHub). 1Password with the TOTP stored inside of it should be good enough for the others.