U2F does use public key crypto (ECDSA).
> because one can carry all the public keys and only a single private key.
Please clarify. Typical pub key crypto usage is that there is a 1:1 mapping private key to public key. Before I go on to smash your argument (j/k) you need to explain this part a bit better.
OPs problem is he needs his crypto keys at all times, because without them, he cannot sign up for a new service AND enroll them all. Now he's forced to carry his backup everywhere, making it just as prone to loss as his primary. Valid point.
Alternatively, if OP could carry a key ring of public keys for all his crypto keys, his backup crypto key can stay home, or in a safe deposit, or buried in a virgin forest of maple trees. While U2F may use ECDSA, or whatever other public key algorithm, it is not possible to carry just the public key and enroll it, is it?
The following is not 2FA, obviously: To illustrate the public key point more clearly, when I sign up for Github, I don't need all my private SSH keys on hand. I only need all my public keys to enroll them, and a single private key to use SSH. If at any time one of the crypto keys is stolen, I can remove the associated public key and use one of the backup crypto keys instead.
Ah.
> While U2F may use ECDSA, or whatever other public key algorithm, it is not possible to carry just the public key and enroll it, is it?
Right, it is not. You have to prove possession of the corresponding private key at enrollment time. A good enhancement to U2F would be to allow cross-attestation. When I enroll, I also sign and send the pubkey (and handle) of other keys I want enrolled at the same time. This requires that enrollment keys not be generated randomly (I have to know which pubkey to cross-sign), but this requirement can be dealt with (for real-world practical uses) on the token side.
I don't know how effectively this addresses the problem at hand. How is it better than a like-keyed backup token whose use automatically invalidates the primary token?
So, what security problems come to your mind if we consider a duplicate token buried at 1 meter somewhere in the forest (and nobody really knows where it might be) ?
With PKI, I contact my spouse. Honey, can you revoke the key I'm carrying? It's been stolen. Thanks sweetie! See you tonight.
I'll admit the duplicate approach makes for a much better movie. The PKI solution is positively boring. Maybe we could throw in a spouse kidnapping to keep it interesting?
Your article makes a valid point about the catch 22 of U2F keys. I simply disagree with your conclusions that it is the user who should try harder to make U2F work. It seems like you are pointing out that U2F is fundamentally broken, but you haven't accepted that yet.