4 ms·
I don’t know what I’m talking about, but isn’t the Secure Enclave already a solution to this? Fido cards just sound like an external solution that all iPhones a
by anuila 6y ago
I don’t know what I’m talking about, but isn’t the Secure Enclave already a solution to this? Fido cards just sound like an external solution that all iPhones and new MacBooks already have integrated (T2)
- dzhiurgis 6y agoSure works when you have only one computer in your life (aka almost nobody). It’s especially bad with Apple with 3 different usb standards. Contactless is the future.
- BHSPitMonkey 6y agoWhat's stopping you from linking more than just one physical FIDO-enabled device to a particular site/service? Most MFA implementations I've seen already allow this, and it seems especially important if you want to minimize the pain of losing/damaging that one sacred card.
- dzhiurgis 6y agoI don't carry any keys so those massive dongles would be pain. Plus must is not ALL which breaks everything.
- warkdarrior 6y agoMobile phones can be FIDO enabled. (see https://developers.google.com/identity/fido/android/native-apps https://developers.google.com/identity/fido/android/native-a... )
- sneak 6y agoAWS, for example, only permits one MFA device per IAM user account. I have four computers and four tokens. :/