33 ms·
Hmm... Isn't that kind of against the whole "FIDO" thing that I've been personally trying to deploy company wide as much as possible. That you have in your per
by bblb 4y ago
Hmm...
Isn't that kind of against the whole "FIDO" thing that I've been personally trying to deploy company wide as much as possible. That you have in your person some actual physical object, what ever it is: YubiKey, SmartCard, a laptop with a TPM chip, a phone.
And your personal private key inside that specific physical object is your "password" that only you can access by PIN or biometric identification.
If you lose access to that physical object, you lose access to the services also. That's the whole point! You can replace it, but then you go through the whole "enrollment" process again. That's another very important point also.
Sounds like a requirement from governments or LEOs. They need access to your private keys and it's much simpler if it's not bound to a physical object anymore. From now on it's just a plain text file on some server, when you backup your phone to the cloud.