Hacker News new | ask | show | jobs
by close04 674 days ago
You probably use certificates and a company PKI to manage them. No need to stress if one is lost or locked, just revoke and whip up a new certificate.

At home Yubikey is probably synonymous to FIDO not PIV/PKI. No whipping up a new one if you lose it. You better have 3 of them enrolled at any time, and have at least one stored off site.

1 comments

We enroll them as standard fido/webauthn - I hate the other modes.

I agree it requires significantly more work when you can't just call the locksmith for a new one -- IT -- if you lose one on your personal account you can only go get the spare key hidden under the doormat, a printed code in your safe, or lose the account.