5 ms·
Props to Hetzner for having this properly integrated with the option for multiple (at least three in my case) hardware keys. For whatever reason, quite often y
by cersa8 4y ago
Props to Hetzner for having this properly integrated with the option for multiple (at least three in my case) hardware keys.
For whatever reason, quite often you can only register a single device (looking at you AWS Root account). The only way around this is by setting up your backup keys with the same OTP private key and use the Yubico Authenticator app to generate the TOTP.
- deleted 4y ago[deleted]
- brian_herman 4y agoI use multiple keys for my google account.
- arccy 4y agoI don't think Hetzner does true WebAuthn? The setup is for the keys to type a password, not a challenge-response involving the browser.
- stavros 4y agoWebAuthn has multiple modes, there's no "true" WebAuthn. You're either using the WebAuthn APIs or you aren't.
- tialaramex 4y ago> quite often you can only register a single device (looking at you AWS Root account). For WebAuthn (and thus FIDO devices) this comes up regularly on HN. It's just AWS. It may feel like it's "everywhere", because it's your Amazon Web Services account, the credentials you use with DynamoDB, the thing you need for your EC2 VMs, the Cloud Computing stuff, your S3 buckets... oh right, yeah, that's all actually just AWS isn't it. It's still a bug, but it's specifically a bug in Amazon's implementation, there is no wider ecosystem problem here.
- mschuster91 4y agoIIRC, Twitter, Google, Dropbox and Facebook also don't allow to enroll multiple Yubikeys (ETA: Looks like I'm a bit outdated). In general, most platforms don't really account for the scenario "my 2nd factor got stolen/robbed/destroyed/lost" beyond also offering a phone app and printed recovery records - and the end result is that a house fire, flood or storm scenario locks out users permanently.
- pchm 4y ago> IIRC, Twitter, Google, Dropbox and Facebook also don't allow to enroll multiple Yubikeys. Don't know about Dropbox, but I set up Yubikeys for Twitter, Google and Facebook recently and they all allow multiple keys.
- mwarkentin 4y agoYeah, that's just false.. just checked and my Dropbox supports multiple as well. AWS is the only one I know of that only allows a single key.
- ArchOversight 4y agoGoogle has allowed you to register multiple keys since they introduced the ability to use security keys.
- psanford 4y agoI agree with your overall point that most of the big services do this correctly, but I do think we'll see more services that do this wrong as webauthn gains greater adoption. Developers are lazy and supporting multiple keys is more work than supporting a single key. Just yesterday I discovered that Thinkst (Canary Tokens) only lets you register a single webauthn token. Thinkst is a company that makes security products! I'm expecting to see this more as adoption picks up.
- tialaramex 4y agoI don't really understand the context in which "Thinkst only lets you register a single webauthn token". Poking around I see some free services (for which I don't need or want any credentials so WebAuthn is irrelevant) and marketing, presumably there's something else here but I don't know what it is. As to the larger point, as well as explicitly telling you to support multiple tokens, WebAuthn is designed in a way that makes the "one single token" implementation pretty unergonomic, which you'd hope would cause anybody who isn't just copy-pasting to think "Huh, I wonder why I need a list of exactly one item here, and this other array with exactly one thing in it, and I have this database table with a column I never use for anything. What a strange design unless... oh right, yeah, we are explicitly required to support multiple tokens". For example, the tokens have a mandatory ID for each enrolment. It's huge (larger than a UUID)! If you're never allowing multiple enrolments it might seem tempting to just forget the ID. There's only one per user, so it's not a problem right? Nope, now nothing works. Cryptographically this now can't work because the ID - while yes it's an identifier and you can totally use it as a PRIMARY KEY in your database or whatever - is also critical to the cryptographic underpinning and so if you've lost it now you can't do WebAuthn. It is of course possible to get it wrong, not really any way around that, but I don't think it's often going to happen by mistake rather than policy.