4 ms·
Don't keep all of your yubikeys and phones and laptops in one bag.
by dfedbeef 1y ago
Don't keep all of your yubikeys and phones and laptops in one bag.
- int_19h 1y agoUnfortunately, many services don't allow you to register multiple passkeys, so having a backup key that is stored somewhere safe is simply not an option.
- chipsrafferty 1y agoThat's why you have multiple passkeys that have the same key. It's a physical backup, not a software backup.
- crote 1y ago... at which point you lose the whole "something you have" part of 2FA. If they all have the same key, it is impossible to distinguish between individual copies, so the compromise of a single copy is impossible to detect. Additionally, you can't revoke a single copy: you are now forced to revoke all of them at once.
- rcxdude 1y agoIs that what you have set up? Can you describe how you do it in more detail? I'm looking for an option like this but everything I've found seems to suggest it's not possible (or at the very least wildly impractical). I'm looking for something where it's at least possible to make a physical backup that's still relatively secure.
- dfedbeef 1y agoYou only need multiple on your recovery email. Unless you're using Yahoo or running your own email server, this is an option.
- dfedbeef 1y agoIt might be possible to set it up on a home server idk. I would rather waste my time on other stupid things.
- esseph 1y agoI have 5 in Google.
- blindriver 1y agoThat doesn’t answer the question, unless it means you’re SOL. If that’s the case why on earth would I prefer passkeys to regular passwords as long as I practice safe password handling?
- dfedbeef 1y agoDo whatever you want. It's easier for me to have a primary recovery email and password manager with MFA that uses a yubikey and phone authenticator. Then I can use passkeys or whatever for the rest of the stupid accounts that I don't care about. Side note: I feel like people always say 'i can just use good passwords' and then their password is like '<sports reference><year>'