"Security keys for Facebook logins currently only work with certain web browsers and mobile devices, so we'll ask you to also register an additional login approval method, such as your mobile phone or Code Generator"
"Security keys for Facebook logins currently only work with certain web browsers and mobile devices, so we'll ask you to also register an additional login approval method, such as your mobile phone or Code Generator"
So as usual, the U2F standard being adopted by companies these days is only as strong as SMS 2FA, because of this requirement.
Can someone tell me what's the point then? Is it that they hope that in the end U2F will get popular enough that they'll remove that requirement? I would hope that's it. Otherwise, I don't see the point.
I wish they at least allowed you to opt-out of the SMS back-up before you even had to give them your number. Of course, we're talking about Facebook here, so they won't waste any opportunity to make it seem like you have no choice but to give them your phone number.
(It's very possible that I'm dumb!)
You would also need to turn off login notifications (section just above login approvals in the security settings page.)
A requirement to have one backup, which doesn't have to be SMS. It appears to allow a manually pregenerated list of codes, for example. See the ui: https://scontent-dft4-1.xx.fbcdn.net/v/t31.0-8/p720x720/1617...