|
|
|
|
|
by lvh
1954 days ago
|
|
Can't speak for this thing specifically, but FIDO2 keys in general: - Yes, you have everything you need on every major OS/browser - These devices are zeroconf; resetting it actually kills a security feature (key use increments) aiming at cloned devices - The ideal backup for this is to have a separate key, both authorized. They don't need to have the same material, in fact, cloning it would be considered a weakness (how do you know someone hasn't cloned it without your knowledge?) |
|
This in particular is important. Security is only as strong as your weakest link, so any backup methods (e.g. "forgot password" flows) might as well be your primary method, if you actually care to strongly secure things.
Adding another (or more) key gets you same-security redundancy if one fails or is lost. Nothing else will achieve this.
Degrading to "forgot password" may be entirely fine for [person's] use of a security key, but you must be explicit about that decision, or it's mostly security snake-oil.