6 ms·
Another side. I always worry more about being locked out by 2FA (a main use case of non-discoverable FIDO keys) as a consequence of lost/retired-then-forgotten
by cvhc 2y ago
Another side. I always worry more about being locked out by 2FA (a main use case of non-discoverable FIDO keys) as a consequence of lost/retired-then-forgotten keys.
This happened once when the US custom detained my electronics, including a Yubikey. Later I managed to recover many accounts that accept email for 2FA or as the ultimate auth factor (i.e., password/2FA reset). But a few, including AWS, doesn't allow that.
Many websites encourage you to enroll 2FA without clarifying the alternative factors and the consequence of lost access.
- berdario 2y ago> the US custom detained my electronics, including a Yubikey Can you elaborate on what happened? I know that it's theoretically possible, but I thought that: 1- They would potentially detain only devices that they can extract information out of (even if encrypted), like a laptop or some hard disk... Yubikey (at least the old U2F-only ones) don't have anything that you can extract 2- They would eventually return the device to you (unless guilty of some national security violation?) Am I mistaken on both counts?
- vanchor3 2y agoIf they just seize it, it will typically be returned at some point. If they decide it's subject to forfeiture, it is now their property. You can contest this with the forfeiture department but I guess if they decide the item is guilty of a crime or other excuses to keep it there's nothing you can do.
- plagiarist 2y agoThat's right. It will be United States v. Some Person's Yubikey. And you can hire it a lawyer if you want, because they will NOT give it a public defender. Massive violation of Constitutional rights if you ask me.
- cvhc 2y agoFor 1, tbh I don't know the rules. technically it was a regular model and can store some data. Or maybe they simply suspected it's a usb disk. And 2 was true. But it was after weeks, and of course I didn't wait until then to reset my account credentials.
- heavyset_go 2y ago> Yubikey (at least the old U2F-only ones) don't have anything that you can extract Newer Yubikeys hold secrets that, if exfiltrated, give you access to accounts. I assume that if it doesn't already exist, there will be a Cellebrite-like device that governments can plug Yubikeys into to dump keys quickly like they're able to with cell phones.
- vaylian 2y ago> 2- They would eventually return the device to you (unless guilty of some national security violation?) "Eventually" is not good enough. People take things with them on their trips, because they expect to use these things while they are traveling/doing work at a remote location. Imagine you need to do some work on a remote site and you can't log in to your company's network, because the TSA has taken away your key so that they can inspect it.
- londons_explore 2y ago> without clarifying the alternative factors This is super annoying. I wish sites would standardize on a simple infographic saying: You will be able to access your account with: * Username, Password and 2FA device. or * 5 points from the following list: Username (1), Current password (2), old password (0.5), sms verification (1), mothers maiden name or other secret word (0.5). Email verification (2). 2 factor device (2), Video call with support agent showing government ID matching account name (1), has waited 7 days without successful login, despite notifying all contact addresses (2) For added security, you can adjust the account to require 6, 7 or 8 points from the above list, but please be aware doing so might hinder your ability to access the account if you lose your password or 2FA device.
- throwaway48476 2y agoUnfortunately identity systems have adopted security through obscurity instead. They use IP address, location, time since last login, number of attempts, device etc to determine how easy to make it for you to log in. I lost a Gmail account because I no longer had an old phone number even though my password was correct.
- willis936 2y agoMaintaining a phone number is not security through obscurity.
- throwaway48476 2y agoThe obscurity is that you have no idea what is required to log in.
- inquirerGeneral 2y ago[dead]
- rodgerd 2y agoThere's a reason that Apple won't let you enable FIDO keys without having two of them to enroll.
- jopsen 2y agoMost sites let you print recovery keys. Print those keys out, and bury them in the backyard (or something like that). Or always add two keys.
- alecco 2y agoYou should always have more than one 2FA. Especially for anything Google as you'll never ever recover the account (unless you are famous or go viral <1%).
- gabeio 2y ago> But a few, including AWS, doesn't allow that. IAM users you are correct only allow a single 2fa key (their way of deprecating IAM users), but their SSO Users can have as many as they want and are honestly much better than IAM users. Even for my personal account I've moved to using an SSO User.
- oasisbob 2y agoI don't think this is accurate - I have multiple MFA devices associated with all my AWS IAM users on multiple accounts of various ages. AWS documentation specifies that users are allowed upto eight MFA devices each: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa_enable_virtual.html https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credenti...
- gabeio 2y agoInteresting, last I bothered with IAM users they were limited to a single MFA "device" virtual or otherwise. https://aws.amazon.com/blogs/security/you-can-now-assign-multiple-mfa-devices-in-iam/ https://aws.amazon.com/blogs/security/you-can-now-assign-mul... Apparently I haven't bothered with them for a few months and didn't notice, glad they finally added it.
- OJFord 2y agoOh I've either overlooked this too (2022, not just a few months) or there's some caveat like 'one of each type' or something. Will have to try again. Presently have a user per key, named with the end of the keys ID so I know which to use, not brilliant but works.