3 ms·
You can’t duplicate hardware MFA keys. You’d have to individually set up the second device everywhere you use MFA, and many services only support a single devic
by bashinator 5y ago
You can’t duplicate hardware MFA keys. You’d have to individually set up the second device everywhere you use MFA, and many services only support a single device (looking at you, AWS).
- buck4roo 5y ago> many services only support a single device (looking at you, AWS). We can (finally) take AWS off that list. I can say I was pleasantly surprised recently by being able to enroll multiple MFA Tokens and device types, for a single IAM SSO User. Don't know the restrictions on it, but https://aws.amazon.com/iam/features/mfa/ https://aws.amazon.com/iam/features/mfa/ probably has more details.
- tialaramex 5y ago> many services only support a single device (looking at you, AWS) I really wish people would stop doing this. It's not "many services" it's one service. "Many women have played the role of Ellen Ripley in the Alien movies (looking at you, Sigourney Weaver)". No. One woman did that and you just named her, not many. Don't use "many" to mean, "Well, one, but when I wrote that it didn't seem like I had a point worth making". If you instead present this as "AWS is broken" then we see what the problem actually is and who needs to fix it.
- lrvick 5y agoThis is inaccurate. You can't duplicate entry level devices like Yubikeys but hardware wallets like Ledger and Trezor both support backup of FIDO seeds in the form of 24 english words you can store endless ways, or recover to a secondary device. I have duplicates of all my MFA keys. These devices are also more secure as they show you the website you are approving on screen to avoid being tricked by malware.