3 ms·
I understand the logic of requiring two keys, but why can't I have password + (security key OR single use code). This is what most services support - for someth
by roxgib 4y ago
I understand the logic of requiring two keys, but why can't I have password + (security key OR single use code). This is what most services support - for something like GitHub I have an authenticator app on my phone or my YubiKey as the second factor, and can use either. That actually provides more redundancy against lost keys/devices than I have now, since if I lose all my Apple devices I'm locked out.
- labcomputer 4y ago> but why can't I have password + (security key OR single use code) That’s actually pretty close to what they support, except that the OPTs are only sent to your trusted Apple devices (you can’t use an arbitrary TOTP app). > since if I lose all my Apple devices I'm locked out They also support a 28 digit recovery key you can print out and a method for trusted contacts to help recover your account.
- roxgib 4y ago> They also support a 28 digit recovery key you can print out and a method for trusted contacts to help recover your account. Suggesting you shouldn't be required to have multiple keys?