Hacker News new | ask | show | jobs
by tialaramex 2199 days ago
The only place I've used WebAuthn/ U2F that did not allow me to enrol multiple keys was AWS. I have two (or more) keys enrolled at Facebook, Google, GitHub, and for my government services.

WebAuthn (which is the one that's actually a documented standard) not only goes out of its way to make multiple tokens practical it explicitly calls out the intent that you should allow users to enrol multiple tokens.

1 comments

Google won't let you enroll with just one key. You need at least two.

Also, if you happen to have a Ledger for crypto crap, those support U2F as well. It's less convenient because you need to connect it to a PC, enter the PIN, and then open the U2F applet.