4 ms·
Wait - the way this works is you have a backup key, if you lose your primary you replace it using your backup. NB this is only needed when you move to a new dev
by nmca 3y ago
Wait - the way this works is you have a backup key, if you lose your primary you replace it using your backup. NB this is only needed when you move to a new device with a new secure enclave too, so at no point is this pizza situation likely.
- Semaphor 3y agoYeah, but you need to add all those secrets to your backup key. So you need to get it out every time you register somewhere.
- GTP 3y agoI have to admit that I don't own an hardware security key. But since those let you use public key cryptography to login, you could at least theoretically use the same public key for multiple services. Whether the FIDO2 protocol lets you do that or not, I admit I don't know.
- donmcronald 3y agoThe keys are baked in to the devices and are tamper proof. So two devices means you have two different public keys. I use YubiKeys for accounts I consider important and they're a pretty huge hassle compared to a password manager. I'm also scared to get rid of any of the old ones I've got just in case they're linked to an account I forgot about.
- GTP 3y agoI thought you could generate a key on your PC and store it inside the YubiKey, are you sure it isn't possible?
- donmcronald 3y agoIt’s possible, at least for GPG. I’m not sure about WebAuthn. Regardless, generating the key right on the device is the most secure way of doing it. It’s also hard to manage keys you’re loading yourself. Once I loaded a private key onto my YubiKey and accidentally failed to backup the private key because I used the wrong syntax when I exported it. I didn’t even realize until I got a new YubiKey and went to load my GPG keys onto it. I was only using it for signing, so it wasn’t a huge deal, but if I’d been using it for encryption / decryption it would have been a disaster.
- lll-o-lll 3y agoIt doesn’t, which would make disaster recovery a huge pain. You would have to register your backup key for every account you have. The Apple/google “passkey” approach lets you use WebAuthn while having encrypted, cloud stored, private key escrow. It is much more convenient. Obviously with the downsides that implies.