5 ms·
But then, once a phone get lost, how do you recover those second factor keys? Or do you mean to have encrypted backup but the "active usage" is on another devic
by yonixw 5y ago
But then, once a phone get lost, how do you recover those second factor keys? Or do you mean to have encrypted backup but the "active usage" is on another device? If so I agree and do the same.
- RealStickman_ 5y agoI keep my recovery keys encrypted with a different password on my desktop. You could also export the 2FA codes from some apps.
- dividedbyzero 5y agoWhere do you keep that password? Rarely-used ones are easy to forget after all.
- yonixw 5y agoI love this comment and this thread. It is literally what happens in my head every time I need to sign up to a new site (having an existential security crisis). Good to see I'm not the only one!
- Aachen 5y agoYeah it's definitely a valid concern, though the considerations for different solutions are a bit too elaborate for me to type out on mobile atm. Some ideas - regularly testing backups also ensures you still have the key material - Shamir's Secret Sharing Scheme, in combination with putting it on paper or multiple devices or... - bank/company vault - hardware security token - give the master keys to the company's master (some tech director) and make it someone else's problem, if you want to be evil :)
- dividedbyzero 5y agoI thought we were discussing personal (i.e. non-work) security? At least that's what TFA appears to be about. Besides, Shamir's Secret Sharing can be outright dangerous even for companies, I really wouldn't recommend that to any private person.