6 ms·
The HyperFIDO Mini (U2F Security Key) is the cheapest and smallest key I've found so far for $10. (Amazon) The Yubico are probably the best key chain candidate
by orbitingpluto 9y ago
The HyperFIDO Mini (U2F Security Key) is the cheapest and smallest key I've found so far for $10. (Amazon)
The Yubico are probably the best key chain candidate. No one wants to trust their key to a weak nylon thread.
You can also set up a Google account to use more than one U2F key.
As for Google 2FA, I think Google caused a lot of confusion by how they set up the Google Authenticator app. Always opt for the text generator codes instead of a barcode. You can then use the code to use on a second Google Authenticator app on another device. Google at one time stated that you could only set up 2FA on a single device, which makes most users leary as one could lose his or her phone.
- nsheridan 9y agoThere's noting stopping you from scanning the barcode multiple times
- orbitingpluto 9y agoDidn't it change the web page on your computer browser after you successfully added it into Google Authenticator? I suppose you could always take a photo of the QR code and then rescan that. Text seems simpler. edit: Anyone else remember this behavior? Old version? Browser specific?
- hdhzy 9y agoIt changes when you input current code. You can scan it multiple times, print it, and then input the code from one of your devices.
- captn3m0 9y agoAlso, if you have a rooted device, you can get the original secret from the SQLite database of the authenticator app.
- garethadams 9y ago"can get the original secret" is a phrase which should worry a security-conscious person
- lorenzhs 9y agorooting their phone is not something a security-conscious person would do, either. Edit: maybe I should have explained my position. There are a few security issues with rooting a phone, e.g.: - rooting usually requires unlocking the bootloader. Once it's unlocked, anyone can flash or boot a custom recovery and modify your system partition. Enrolling your own keys in the recovery and re-locking the bootloader, while possible, is an undocumented and complex process that just about nobody uses, see https://mjg59.dreamwidth.org/31765.html https://mjg59.dreamwidth.org/31765.html . You're also screwed if a system update replaces the recovery. Once the bootloader is unlocked, anyone with physical access to your phone can mess with your system in malicious ways. - it circumvents the system's permission model. A malicious app that tricks the user into granting it root rights (maybe for a legitimate reason) could access information it shouldn't have, install a keylogger, etc.
- tokenizerrr 9y agoEven without root. Just run a backup and extract it from that. You can do it with just adb or helium.
- jeffreyparker 9y agoThat doesn't work for Google Authenticator. Apps can opt-out of being able to be backed up, which even prevents adb/helium backups (unless you're rooted).
- hdhzy 9y agoRemember to add at least two U2F keys. It's easy to lock yourself out in case the only one or lost / broken.
- j_s 9y agoThe HyperFIDO Mini (U2F Security Key) clickable link: https://amzn.com/dp/B00WIX4JMC https://amzn.com/dp/B00WIX4JMC
- tptacek 9y agoSo by switching to a security key that nobody else uses, you've saved $7.99. With that money, you could buy a cup of coffee at Starbucks and have some money left to donate to the change jar.