Hacker News new | ask | show | jobs
by Thorrez 2516 days ago
It depends on your threat model. If you're worried about sophisticated attackers physically breaking in to your place to steal a Yubikey to steal your accounts, you should also worry about them physically tampering with your computer to install malware, and thus need monitoring for that as well.

If you can't do the monitoring, and you face very advanced attackers like this, it's probably best to only use a laptop that you physically keep with you at all times, and then you can keep your Yubikey with you at all times too.

If you just want to protect against an attacker sophisticated enough to steal a Yubikey but not enough to install malware, then maybe instead of a second Yubikey in the safe deposit box, you could have an encrypted recovery code in the safe deposit box, and either memorize the password, or store the password on your computer.

I've never heard of attackers stealing a Yubikey though. More likely is the attacker will social engineer the website's support into giving over your account.

1 comments

I’ve heard safe deposit boxes as an answer to the question “what if my house burns down with my yubikey/recovery code sheet in it, and none of my friends or family are as security-conscious as me so I can’t leave the spare with them”
Yes, fires are one of the main problems that a safe deposit box protects against. But Bucephalus355 seemed to be ignoring them already by considering just having a safe onsite.