It's also easy to get two yubikeys and have a backup ready to use immediately.
As to U2F, there is always a backup method (usually TOTP generated by Google Authenticator, and additionally recovery codes).
U2F? You need to have a second one or backup codes.
OpenPGP? You probably have your subkeys backed up somewhere so you just order a new Yubikey and put your subkeys there.
The same goes to PIV (X.509 certs). If you have some keys generated on the card, you need to provision your new Yubikey from the beginning.
I am less willing to use something like this for passwordless logins. These types of devices should be part of the "something you have" part of 2FA, which should always be paired with a "something you know".
Maybe I'm missing a step here, but why would you ever use this for passwordless?
Note that you quickly get to the point where you need more than one person involved. You can compromise one person as much as you want, but if that person doesn't have the complete secret it doesn't do any good.
A fingerprint isn't “something you are”, because it can be destroyed while you remain, and information about it can be captured and reproduced by attackers who are not you.
It's just a particularly hard to lose (but easy to discover, and impractical to replace if compromised, at least more times than you have fingers) “something you have.” In security factor terms, I'm not convinced the idea of a distinct “something you are” category is coherent, since most candidates seem similar to that.
Yes, what I am saying is that in practice what that term of art refers to is not an independent, orthogonal kind of security factor from “have” and “know” but a strictly worse form of “have”.
Much more effective.
Also, some cryptocurrency wallets, like Trezor and the Nano S, can do U2F. These can be effectively backed up to paper with 12 or 24 word seed phrases, and can serve as a good (if bulky) backup option.
Still, save your backup codes for each site you register.
(And sometime the fine print just seems impractical: I'm unlikely to actually air out my safe for 30 minutes each week, but could replace a desiccant a few times a year.)
Does anyone have a recommendation for a safe that can protect paper documents and digital media from both fire and water in realistic conditions?
Look for UL fire endurance ratings. UL rates them on time and temperature. Edit: I've seen ratings up to 3 hours, but the longer the time, the bulkier and heavier for the same storage volume.
For paper, you'd want something rated to stay below 350 degrees for at least an hour. That's not hard to find even in large sizes. I ended up with a used FireKing 4 drawer file cabinet from a company liquidation sale. Edit: Built like a tank, holds a lot, uses a Medeco key, weighs a couple hundred pounds empty.
For digital, you need something rated to stay below 125 degrees. That's pretty hard to find, and usually only in very small boxes. Unfortunately, some companies (looking at you, Sentry) like to advertise "digital media" boxes which are not rated for 125 when you read the fine print. Not sure how they get away with that. :(
I eventually found a small Sentry chest rated for 125 degrees for 30 minutes. Holds a couple hard drives and some DVDs. Sadly, do not recall the model number. Edit: Storage volume is maybe 5"x5"x8", walls are all 3-4" thick.
I believe this is a bigger barrier for common people who don’t know how to create and retain backup mechanisms. As such, I don’t see a lot of value in recommending these devices to those who aren’t tech savvy without also explaining to them about recovery. So much for technology!
-Static Password
-HMAC-SHA1 Challenge-Response
-OATH-TOTP (Yubico Authenticator)
[1] https://support.yubico.com/support/solutions/articles/150000...
I primarily use them for u2f and totp, though I want to deep dive into ssh via OpenPgp one of these days. When I want to add a new site, I: 1. Set it up on my keychain key. 2. If at home, set it up on my backup. If not, print out the totp secret on paper and when I get home, add it. 3. Call my parents and ask them to plug the 3rd key into a windows box I can Remote Desktop into and set up either totp or u2f via Remote Desktop. Once done, I ask them to unplug it (it’s attached to the desktop pc case with a lanyard).
I find the “key at parents house” to be really helpful, as if I’m traveling and lose/destroy my keys, I can just call them and ask them to plug it in and then I’m back in business.
corollary to this is that you shouldn't ever get only one.
If I get the new Yubikey, my plan is to put the old one in a safe as a backup.