Hacker News new | ask | show | jobs
by rgreen 1147 days ago
hard disagree. my favorite workflow for high value accounts is webauthn backed by secure enclave with hardware key backups. it's really low friction from ux perspective and it frustrates me when sites don't support it.
1 comments

what's your key backup/recovery strategy?
recovery is easy. i'm a customer of all these companies so i have faith i'll be able to convince them i'm me if it comes to that. and i keep a handful of hardware keys to make self-recovery easier if i lose or break one. most of my practices are to mitigate risks i personally know how to mitigate, and doing it while causing myself as little headache as possible. being able to auth using touch id on my personal laptop is great for day to day usage.
Also, if you use iCloud for passkeys, Apple has has a procedure to regain iCloud access with a recovery contact:

https://support.apple.com/guide/security/account-recovery-co...

(No, that doesn't mean that the contact has access to your account, the encryption key is split between the contact and Apple by the device.)

So I assume you do not consider, say, your Github or Google account to be high-value? Plenty of tech companies have simply started to refuse recovery if you lose all your 2FA keys.
What do you do without 2fa if your account is taken over? I’m trading that risk for something more in my control. Yeah it would suck if I lost all my hardware keys, my laptop, and paper backup codes, and additionally I couldn’t get support from anyone.