Security Key for safer logins with a touch
facebook.com
Security Key for safer logins with a touch
1–10 of 105 posts
Re: Security Key for safer logins with a touch
#2Re: Security Key for safer logins with a touch
#3Re: Security Key for safer logins with a touch
#4This is great forward progress, I much prefer U2F where available. I hadn't even realized that FB supported 2fa, so I just tried to set it up on my iPhone, and either automatically or manually cannot get a test code to work. This tends to reduce my confidence in any other aspect of their implementation
Re: Security Key for safer logins with a touch
#5Does it rely on SMS as backup, though?
"Security keys for Facebook logins currently only work with certain web browsers and mobile devices, so we'll ask you to also register an additional login approval method, such as your mobile phone or Code Generator"
Re: Security Key for safer logins with a touch
#6Does it rely on SMS as backup, though?
It looks like it gives you a choice: "Security keys for Facebook logins currently only work with certain web browsers and mobile devices, so we'll ask you to also register an additional login approval method, such as your mobile phone or Code Generator"
So as usual, the U2F standard being adopted by companies these days is only as strong as SMS 2FA, because of this requirement.
Can someone tell me what's the point then? Is it that they hope that in the end U2F will get popular enough that they'll remove that requirement? I would hope that's it. Otherwise, I don't see the point.
I wish they at least allowed you to opt-out of the SMS back-up before you even had to give them your number. Of course, we're talking about Facebook here, so they won't waste any opportunity to make it seem like you have no choice but to give them your phone number.
Re: Security Key for safer logins with a touch
#7Re: Security Key for safer logins with a touch
#8Another U2F hardware key is the Trezor bitcoin hardware wallet ( https://blog.trezor.io/secure-two-factor-authentication-with... ) which has the added benefit that you can backup all your U2F private keys. I'm not aware of how you could do this with a Yubico U2F key -- if someone knows, please enlighten me.
Re: Security Key for safer logins with a touch
#9Earlier quoted context omitted.
It looks like it gives you a choice: "Security keys for Facebook logins currently only work with certain web browsers and mobile devices, so we'll ask you to also register an additional login approval method, such as your mobile phone or Code Generator"
That looks like a requirement, not a choice. So as usual, the U2F standard being adopted by companies these days is only as strong as SMS 2FA, because of this requirement. Can someone tell me what's the point then? Is it that they hope that in the end U2F will get popular enough that they'll remove that requirement? I would hope that's it. Otherwise, I don't see the point. I wish they at least allowed you to opt-out…
Re: Security Key for safer logins with a touch
#10That said, I understand the lack of support since I am an extremely small niche, and this did prompt me to finally add 2FA to facebook (U2F and code generation from my Yubikey Neo)
[1] https://addons.mozilla.org/en-US/firefox/addon/u2f-support-a...