Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How do you handle adding both keys if you store them in different locations?

Right now I do something similar, but I have to keep a list of which accounts I need to add to key 2, and the key is offsite, so I have a several week period during which an account only has one key associated with it.



I have one key permanently plugged in to my desktop at home. I have another on my keychain that I can use at work or if I'm travelling or whatever. This allows quick access to a yubikey anywhere I am. My previous problem (when I owned only 1) was that my keys were always in another room when I was home, and getting up to get them was too annoying when logging in to things. Now I have a backup if either is lost and I'm more-or-less guaranteed to have a yubikey within reach anytime it's needed.


you don't necessarily need two security keys. written down backup codes or an authenticator app are also good second factors.


If you can just fall back to authenticator app by saying "oops don't have yubikey now" then you get no extra security for using a yubikey.


You may consider that the authenticator offers enough security but a Security Key is more convenient. I hate typing 6-digit codes into things, touching the little contact or pressing the button on my Security Keys is much more tolerable.

Now, personally I wouldn't want the phishable Authenticator as fallback, but it's definitely better than SMS for example.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: