|
|
|
|
|
by Thorrez
2516 days ago
|
|
It depends on your threat model. If you're worried about sophisticated attackers physically breaking in to your place to steal a Yubikey to steal your accounts, you should also worry about them physically tampering with your computer to install malware, and thus need monitoring for that as well. If you can't do the monitoring, and you face very advanced attackers like this, it's probably best to only use a laptop that you physically keep with you at all times, and then you can keep your Yubikey with you at all times too. If you just want to protect against an attacker sophisticated enough to steal a Yubikey but not enough to install malware, then maybe instead of a second Yubikey in the safe deposit box, you could have an encrypted recovery code in the safe deposit box, and either memorize the password, or store the password on your computer. I've never heard of attackers stealing a Yubikey though. More likely is the attacker will social engineer the website's support into giving over your account. |
|