3 ms·
It’s really up to the user to determine whether it’s worth it for them. I work in security, so I eat my own caviar in my personal set up and like to test things
by mlac 5y ago
It’s really up to the user to determine whether it’s worth it for them. I work in security, so I eat my own caviar in my personal set up and like to test things out.
All hardware dies, but I also have different keys from different vendors (not just yubico), purchased at different times. The likelihood that all 3 die at the same time is very low. Whether it prevents an attack that would be successful without the physical key (e.g. SIM takeover) is something I won’t ever know. Both of those scenarios are very low likelihood.
But to have this level of security requires extra work, and part of that work is regularly testing that the keys still work. With the increasing account lockouts, this thread is showing me that physical keys may have another advantage.
Most people are set up so that their email account is a “Jesus Nut” [0], so this extra level of security is well worth it as it protects banking, personal files (g drive & photos), password resets / password manager, and purchasing capabilities.
An approach I like is using one’s birthday as a reminder to reset important things - check security keys, check batteries in critical items, test security system, etc.
[0] https://en.wikipedia.org/wiki/Jesus_nut https://en.wikipedia.org/wiki/Jesus_nut
- AnonC 5y ago> But to have this level of security requires extra work, and part of that work is regularly testing that the keys still work. This is a late reply, but thanks for your detailed response. I agree that this requires extra work, and that it is important. But the cost of multiple hardware keys also add up. So I doubt if this is a solution for the masses (of course, I'm not implying that anyone who's concerned about losing an account shouldn't spend some money and time). If you do see this reply, I'd like to know the other vendors (apart from Yubico) whose keys you use.