Hacker News new | ask | show | jobs
by girvo 2310 days ago
I definitely would like the requirement to allow multiple keys to be a part of the standard. Allowing it at the key level seems dangerous to me, perhaps, in allowing an attacker to perhaps "clone" someone's key that hasn't setup a pair yet, though of course I'm sure there's mitigations for that if it was seriously proposed!

I have two Yubikeys, one in a safe and one on my person. It saved my butt when I lost access to the one on my person for a few days!

1 comments

The fido2 protocol involves a counter that allows the server to detect cloning of a device :)