3 ms·
Sure, not being clonable is a security feature, but it's a huge pain to keep multiple keys registered on all of your services. For real backup resiliency, you
by balazer 5y ago
Sure, not being clonable is a security feature, but it's a huge pain to keep multiple keys registered on all of your services.
For real backup resiliency, you should have at least 3 keys, one of which you keep off-site. Presumably you keep one at home and one with you. Want to sign up for a new service? I hope you're at home where you can access two of your keys to register them. Then sometime later you need to go to your off-site location to swap that key, bring it home, and get it registered also. Do that periodically so all of your services are on all 3 keys.
Unclonable hardware keys work well enough when it's for a corporate service. Lose the key? Just visit IT and have them give you a new one or overnight it. But unclonable hardware keys are a huge pain when used personally with multiple services.
TOTP secrets, while less secure, are much easier to manage. You can write them down, store them on a USB stick, or store them in an online account. You can send them in a message or even read them over the phone. Ultimately the average user is more concerned about losing access to their account than being attacked by a nation state.