4 ms·
At this point I think the thing holding back U2F is just user experience. It is not "hard" but it is a pain in the ass and most people just find it annoying. T
by thinkharderdev 5y ago
At this point I think the thing holding back U2F is just user experience. It is not "hard" but it is a pain in the ass and most people just find it annoying.
The other issue is that you ultimately need some sort of fallback mechanism if someone loses their keys. And it will happen. So you still end up with a process that can be socially engineered, which is generally the weak link in any authentication system.
- sneak 5y agoThe pain in the ass is why it should be used as an primary app-based 2FA recovery mechanism. Doing 2FA via app is fine for most users. The failures happen when users lose their phone and need to reset 2FA. That's where the pain in the ass (but secure pain in the ass) of U2F would come in handy, to re-enroll primary 2FA. Nobody presently has good ways of doing 2FA resets. U2F hardware is a near-perfect solution.
- thinkharderdev 5y agoIt's a near perfect solution assuming nobody ever loses their U2F device.
- moepstar 5y agoThis is why you get two, one primary and one backup - they (Coinbase) actively encourage you to enroll two (or more, i think the limit is 5 or 6). Also, their mobile app recently was updated to support NFC Yubikeys...