3 ms·
You don't have to be tied to a single device. A common set up is a root yubikey you create children of. The root key is held in a safe location and the childre
by AeroNotix 4y ago
You don't have to be tied to a single device. A common set up is a root yubikey you create children of. The root key is held in a safe location and the children have either copies or even better, short live keys signed by the root.
- account-5 4y agoI'll have to take your word for it. That all seems complicated to me, maybe it's not and is just out of my frame of reference.
- sebk 4y agoYubiKeys can't have copies of themselves, that's a big portion of their selling point. As far as I know and strictily in FIDO, there is no solution here. The closest that Yubico has is this draft: https://github.com/Yubico/webauthn-recovery-extension https://github.com/Yubico/webauthn-recovery-extension which will roughly make an authenticator register two keys with an RP. The draft itself is not implemented anywhere as far as I know and while better than the current state of hardware key backups, it's still not problem free. I personally would love to see it implemented, so it can be used for logging in to the service that provides a WebAuthn sync fabric.
- sigzero 4y ago"passkeys in YubiKeys are bound to the YubiKey’s physical hardware where they can’t be copied." Unless you are talking about something entirely different that scenario isn't possible.
- waych 4y agoI don't know about this "root key" setup you describe, but you can certainly program sets of yubikeys with the same OTP secrets at setup time, resulting in cloned/backup keys. The OTP secrets can also be stored (presumably offline) to create new copies of the key in case of recovery.