Hacker News new | ask | show | jobs
by EvanAnderson 6 days ago
Speaking about hardware tokens:

If I have to go get the backup out of "secure" storage each time I want to add a new Passkey it's not really a backup.

The design should have allowed, even if it was just within only the purview of a single manufacturer, a method for the device to export an encrypted dump that could be reloaded onto a factory-new device. Heck, make it a value-added service that the manufacturer has to initiate and tie it to some real-world identity verification.

The idea of having to put backup devices in-hand regularly is a bad design.

Phone apps. get around this idiocy by backing-up the encrypted Passkeys to a hosted service.

1 comments

> If I have to go get the backup out of "secure" storage each time I want to add a new Passkey it's not really a backup.

Yes.

> even if it was just within only the purview of a single manufacturer

> Heck, make it a value-added service that the manufacturer has to initiate and tie it to some real-world identity verification.

No.