Hacker News new | ask | show | jobs
by derekp7 1653 days ago
Ideally I'd like to be able to register my physical token with the manufacturer and have them send me a replacement based on sufficient identification. Things like ordering the replacement with a credit card in my name, sent to my mailing address, vouched for by a notary public, and/or anything else that I check off on the list of factors I find acceptable when I send them my registration form.

The alternative is for me to use TOTP and have the secrets printed out, lightly encrypted, and stored in a safe deposit box.

1 comments

In order for this plan to work, the token manufacturer would have to be able to store your secrets, which means you uploading your secrets, which defeats the purpose of physical tokens. Just use a cell phone number one-time-code or authenticator app with time-based-codes instead.