|
|
|
|
|
by tialaramex
2190 days ago
|
|
Just because you're allowed to do OTP backup doesn't require you to switch it on. If you have two FIDO keys that's fine. What isn't fine is one FIDO key and no other backup. The good ones aren't fragile, but you can still easily lose them. If there's a site you use on the phone too, newer Android devices which know how to keep a secret (e.g. a Pixel) can do WebAuthn for themselves and be that second option for you. |
|
It does make a bit of sense. Users can't be trusted not to lose their single token. But rarely is the option to enrol a second u2f key as backup permitted.