|
|
|
|
|
by pricechild
2192 days ago
|
|
I think the point was that most u2f implementations around don't just allow OTP as backups... they require you to set up OTP first before u2f can be enabled. It does make a bit of sense. Users can't be trusted not to lose their single token. But rarely is the option to enrol a second u2f key as backup permitted. |
|
WebAuthn (which is the one that's actually a documented standard) not only goes out of its way to make multiple tokens practical it explicitly calls out the intent that you should allow users to enrol multiple tokens.