Hacker News new | ask | show | jobs
by mabbo 2816 days ago
Maybe I'm misunderstanding, but I thought the whole idea of ubikey was that it proves who I am because I have it, no? If I own 4 ubikey, how does the system know whether I'm really me, or if I'm someone whose stolen one of my ubikey?
2 comments

If you have one Yubikey, how does system know if it’s really you or someone who stole your key?
It is a second factor, so the'll also need to know your password.

You will notice your key missing, then you can disable that key with your backup key. With only a password, it becomes a lot harder to notice someone stole your pw.

Right. That also applies to N number of keys, too.
The different is, if you have 1 U2F key, people who steal your U2F key gain access to one half of the two factors for ALL services you use.

With 4 U2F keys, people who stole 1 of your U2F keys gain that one factor for only the services that you tied to that keys.

U2F is much narrower than full Yubikeys.