3 ms·
While this is true, the spirit of the GP is correct. To login you will need both a username/password and the second factor. So losing the key is still relevant.
by nerdwaller 6y ago
While this is true, the spirit of the GP is correct. To login you will need both a username/password and the second factor. So losing the key is still relevant.
In practice that means people really need to buy (at least) two yubikeys to register with services that allow it. Have one on something that’s always with you (such as keys) and the extra(s) as a backup somewhere secure. Unfortunately this works with most accounts except the big one I want it to... AWS.
Some sites allow you to also register a standard MFA device as a fallback, and further still Google (as an example) allows you to use another device that’s already authenticated to get a one time use code (depending on your account security setup).
- paulie_a 6y agoAlso google also allows for a list of recovery codes.
- sneak 6y agoTo sidestep this, create a new AWS account to be your master SSO administration account (separate from whatever account you're already using), and enable "AWS Organizations" in it. Join the existing AWS accounts to the new "AWS Organization". Once you enable AWS SSO for the "organization", you can then set up SAML SSO to your existing identity provider (e.g. G Suite, which allows multiple hardware 2FA tokens per user). You do this in the new master organization account. You can create the corresponding users in AWS SSO, and grant them the appropriate permissions in the appropriate organization accounts. Then you do the 2FA auth to your IdP (G Suite, or selfhosted, or whatever) and then AWS just trusts the auth from the IdP, and you get to sidestep the terrible morass that is AWS MFA configuration. If you get stuck, email me.
- nerdwaller 6y agoI’m going to have to take a look at this, this sounds awesome thank you!