3 ms·
How many websites allow U2F as the only 2FA? Every website I tied it wanted a backup authentication app added.
by 8ytecoder 6y ago
How many websites allow U2F as the only 2FA? Every website I tied it wanted a backup authentication app added.
- dathinab 6y agoNormally you can create backup hardware recovery keys (or alternate fallback 2F). (EDIT: Keys as in e.g. alphanumeric on time use tokens lie "23430240392") This is necessary as you would else wise be permanently be locked out if you lose your U2F key. That is assuming you can't reset your U2F key using mail password recovery. But your mail being a single point of failure is something U2F normally tries to prevent. Through I guess for not relevant services. I would still want U2F but allow mail recovery and maybe even U2F _only_ login (or FIDO login without PIN). Given that people have different opinions about what is important I guess this should be an option for fallback recovery, maybe with some warning around it. The "workaround" to have no fallback for U2F is to generate recovery keys and then not store them anywhere ;=). But I would not recommend this, except if they have a insecure mail based password/U2F recovery anyway.
- chaz6 6y agoI have 4 keys which are stored safely. I do not want a fallback mechanism because that reduces the security of my account. The downside is I have to manage my keys on each site separately. It is a shame that the original OpenID never stuck around as I could have just had one secure account, without having to be part of the current ID provider cabal.
- AnonC 6y agoOr perhaps worse, they want SMS OTP to be added as a backup. Even with tons of messages telling people not to share OTPs, it still happens through social engineering.