Hacker News new | ask | show | jobs
by obelus 812 days ago
I personally keep a Yubikey on my keychain (pin protected) with backups for critical webauthn/passkeys.
1 comments

That requires being able to plug in your device, right?

How many such keys are needed? I'm guessing about 5? Give a couple to trusted friends, in case my residence burns down, keep one with me, and two at home as backup, because I know I'll lose things?

How often should I verify they still work? (Backups don't exist until you've restored, so I assume the same applies here?)

Everything I see about passkeys makes me think the failure mode can be more tragic than using passwords, and the use case is for people willing to trust Apple or Google.

I think I'm willing to trust Proton - for one, they support deGoogled Android - but I don't understand the risks in switching, or what backup practices I need.