Hacker News new | ask | show | jobs
by viraptor 2515 days ago
Why would you want to store yubikeys securely, as opposed to recovery codes which you can print out in multiple copies? Store it in multiple semi-secure places. Unless you're running infra for an international corp, government, bank, or are likely to be physically targeted for some reason, you can likely store it in a folder on a shelf.

(And if you actually need to worry about things like that, then you've got (or should have) people who think of things like that for you)

1 comments

You can check to see the key is still there but you can't check to see if anyone has copied the codes. The key is meant to be not possible to duplicate.
There are many ways to make it easy to see things have been tampered with.
Greatest trick i heard is a simple paper seal, sprinkled with glitter, and then varnished with nail polish. Take pictures of the seal, and compare the seal against the picture.
...but not that many that guarantee/clarify if something was read/duplicated. That’s what a safe would buy you.
No, I really mean "many ways". Just search for tamper evident products. There's a huge number of ways you can get that guarantee. For example this: https://harcor.com.au/products/security-seals/tamper-evident...
Lots of ways to set markers against all but seriously professional adversaries. I’d personally worry more about losing access to your key/combination.

Frankly your main threat is probably a fire or flood. Not a Russian agent breaking into your house.