I haven't carried a thumb drive in a while, but I personally have lost a couple before...
I haven't carried a thumb drive in a while, but I personally have lost a couple before...
- For use as a key storage device / GPG smartcard, you should have the usual contingencies in place (e.g. backups of decryption keys, alternative signing/auth keys). Only GPG nerds are likely to use this feature.
- For MFA use, you can list an additional device as another acceptable factor. E.g. a second key, or an authenticatior app on your phone.
The Heads boot validation stuff is non-blocking; you can still boot into a system without verifying the boot partition/BIOS. Alternatively, there’s no reason you couldn’t fall back to TOTP on a phone, though I’m not sure if the interface supports that currently.
Source: I put everything on a YubiKey, then lost it.
* You buy multiple devices and configure your systems to honor both, as a backup plan.
* You back up your keys or their artifacts to paper or a small drive and keep that somewhere safe.
If you do neither of those things, and you lose the hardware key, you are either (a) boned or (b) using an insecure system where the key is just theater.
Some services allow you to configure multiple separate keys, so different private keys. Lastpass for example.