Right now I do something similar, but I have to keep a list of which accounts I need to add to key 2, and the key is offsite, so I have a several week period during which an account only has one key associated with it.
Now, personally I wouldn't want the phishable Authenticator as fallback, but it's definitely better than SMS for example.
You will notice your key missing, then you can disable that key with your backup key. With only a password, it becomes a lot harder to notice someone stole your pw.
With 4 U2F keys, people who stole 1 of your U2F keys gain that one factor for only the services that you tied to that keys.
Maybe techie personal users have more than one, but I only carry one device (a yubikey) for work, someone at work can reset my MFA if I lose it.
I'd be surprised if "most" people have a backup device/codes.
It’s also helpful when you use a key that lives in a machine to not have to remove it. If you lose the machine, use another key to sign in and disavow the lost key.
If I have one key and someone takes it, I know it immediately.
If I have 2 keys and someone steals my spare, then I might not realize it for quite some time.
With AWS you are the company, and you should be allowed to set your own policy, and decide things like whether you trust yourself enough to store a backup key in a safe or something similar.
Suggesting Amazon should treat you like some employee of theirs is silly.
But for personal accounts, solo founders, travellers etc this is a no-go.
Really? I'd expect someone who's paying $50 for a yubikey to spend another $100 to have a backup key, a key for their laptop, and one for their desktop. Add another one for your keychain if you are using it on your phone (if your phone supports it).
It stores your secrets in plain text on the phone without any secure enclave. If your backup password is sniffed or there is a flaw in Authy or your mobile OS sandboxing fails you are toast.
I use Authy to manage my 2FA codes, but I rarely ever use the desktop app. I stick to my phone to keep a physical separation between my logins and my 2FA app.
I also started storing my backup codes as a base64 encoded gpg password encrypted text file in my password manager. If I ever lose my 2FA codes I can still get into my accounts in a emergency while also protecting myself from a password manager hack.
It's annoying, but as I said, I'm not willing to take the risk.
Convenience is the enemy of security. I think you're making a good choice though. It's a minor inconvenience for increased security and peace of mind.
If my 1Password vault is breached, I am pretty much in a world of trouble as it is.
I have to remember three passwords (oh no!) and feel safer for it. It could all be in my head, though.
If someone gets into your 1Password it’s all over anyway.
That said, I pay for the standalone app and store my vault myself. I have no actual reason not to trust AgileBits hosting it, but they must be a huge target and I’m not taking my chances.
I used to be a Keychain + Authy user but moved everything to 1Password.
With Yubico's authenticator, you store the secrets ontp your Yubikey. This means you can reset your phone and still be able to use the same TOTP shared secrets. Or if that matters, ask a friend to install the app and use your Yubikeys to get the TOTP.
You now have a backup login, it just has a different username too.
AWS EKS is a good example for anyone who has had a play already.
We eyed on switching from kops to EKS. But immediately stepped down after experiencing so many issues.
Why?!?! :(
LastPass for example
If all they managed to do was trick me into entering my master password on a dummy login page, the sort of phish that U2F is designed to protect against, U2F would still keep me protected while OTP wouldn't.