Hacker News new | ask | show | jobs
by srigi 1250 days ago
The idea of FIDO2 with HW tokens is great, but not practical if you don't own atleast 2 pieces: - one constantly inserted into main working machine - second somewhere with the keys, ready to be used on other devices

You should be having third one - backup token stored securely in the safe or vault. That is $150 investment just to do it right.

And then - not all webapps allow to register more that one FIDO2 device, which totally cancels the above best practises.