3 ms·
The disadvantage of this approach is that you can't invalidate those devices individually - if one is compromised (i.e. lost), they're all compromised.
by roxgib 4y ago
The disadvantage of this approach is that you can't invalidate those devices individually - if one is compromised (i.e. lost), they're all compromised.
- Brian_K_White 4y agoI don't see hlw this makes any difference vs a single device. If I only have a single device set up, and I lose that device, I still have to go to all the configured sites, only now without my auth app. What prompted me to figure out how to clone the setup was when my phone screen broke while away from home, and 2fa enabled on both google and Ting. I couldn't even just buy a new phone because how could I migrate the number? Luckily I never had to find out if Ting has an answer for that, since I was able to get the screen replaced without wiping the phone. I wasn't really screwed because I did have recovery codes for Ting in keepass, and had access to that. And that would have allowed me to move my number to a new phone, where I could once again receive sms to recover everything else. But I did not have recovery codes for anything else, because I just didn't fully understand the process when I first set them up, so for a few other things, I was maybe almost screwed if I couldn't regain access to that one special golden device. So, no more one special golden device.