4 ms·
I configure a second YubiKey as a backup, and disabled SMS-based recovery where possible. Many sites allow this explicitly, and will let you view details about
by zjs 8y ago
I configure a second YubiKey as a backup, and disabled SMS-based recovery where possible.
Many sites allow this explicitly, and will let you view details about the last time each key was used to log in.
Some sites that use TOTP only allow for one "authenticator" to be configured. In those cases, I scan the same QR code into each key.
This process requires you to retrieve your backup key from whatever safe place you store it in when configuring 2FA on new accounts, but that feels like a reasonable trade-off; I don't make new accounts very often, and when I do I can wait to configure 2FA until I have access to my backup key.