3 ms·
> People are incredibly laissez faire about their yubikeys - leaving them plugged in, leaving them on their keys, etc. You can (should) protect your YubiKey wi
by konha 4y ago
> People are incredibly laissez faire about their yubikeys - leaving them plugged in, leaving them on their keys, etc.
You can (should) protect your YubiKey with a pin. They will lock/reset after a couple of failed attempts.
> On top of that, most sites that "support FIDO", including google, will almost always be configured to fall back to other means.
Google accounts can be configured to require hardware tokens for 2FA without fallback to less secure methods. [0] Apple has a similar program. [1]
[0] https://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/
[1] https://support.apple.com/en-us/HT212520 https://support.apple.com/en-us/HT212520
- trompetenaccoun 4y agoFair enough but at that point, why not just use a software based PW manager?
- foobiekr 4y agoYes, you can configure google that way. People mostly don’t, however. Yes, you can (and should) configure a pin. Now you have a DOS problem.