YubiKeys only seem to make sense in a corporate environment where you can always request a new YubiKey and reregister it based on your ID.
YubiKeys only seem to make sense in a corporate environment where you can always request a new YubiKey and reregister it based on your ID.
Or, you have a set of one-time codes for recovery. I have accounts with a lot of sites, and all the sites that support proper U2F did have one-time recovery code option, because that's the fallback system that makes a lot of sense together with hardware tokens. Yes, the sites that support only things like phone-based OTP usually don't bother, since their risk model anyway puts all the trust in the phone so they usually just have a phone-based fallback, e.g. SMS with all the security risks related to that.
Or, you initialize two yubikeys so that they're identical; so you use your primary key and store the backup key somewhere safely, this doesn't require you to register multiple keys at each site, so it's a bit more convenient but it makes revoking a lost key a much bigger pain.
Then, use GSuite to sign into other services (like Slack) wherever supported to minimize how often you need to do this.
We're amongst a very technologically educated part of the population here, and honestly, I'm not sure about the scope of Google Authenticator. Quite sure that many aren't.
If you can extract the private key, you can transfer it to another phone or device.
On Android, AndOTP is open source (available on F-Droid) and allows encrypted backups. As for Google Authenticator, I don't think you can create backups.
To watch setup videos see https://onlykey.io/watch
So, if you lose your YubiKey, you can still login 10 times using a recovery code. Presumably during those 10 times you either disable 2FA or register a new YubiKey.
Edit: And let me just add why I think this is relevant. Even though few people have dedicated hardware keys today, many 2FA schemes depend on being in possession of a particular phone. There are typically no backups and no recovery codes.
I don't think this would necessarily change if specialised key hardware was used more often. In fact, my business bank account and a broker I previously used both require hardware keys and do not provide recovery codes.
But many other sites have no other alternatives to recover so the recovery codes are a nice solution.
Note that I dislike that my bank gives me their specific hardware token. I am not sure why I couldn't use a 'standard' Yubikey instead.
Recovery codes go straight into the password manager, right next to my mother's maiden name, ASuTeil7quoongak2aeniVar.
The recovery code, just like the hardware 2fa, does not work unless you know the password. So you want to secure against people that live with you, know your password and from whom you cannot hide anything anywhere?
The printout is the size of a business card. You could put it in your Bible as a booksign an nobody would find them. Or if you want you could rot13 them or something basic so they can't be used as-is.
Actually, what are you suggesting instead? I'm genuinely curious what flawless solution you found.
Also no, you're not genuinely curious, you're trying to waste someone else's time.
So, you are against things. What are you for?
home keys and yubikeys are both hardware keys and same rules apply - you absolutely should have more than one.
The same way physical keys protect your home even when you lose them - you have spare keys for that event.
How much would it cost to pay someone to "break open" my GMail account if I lost access to all my second factors? I'm guessing more than the ~$150 a locksmith would charge me to break into my house. Probably a number of zeroes at the end more.
But even in the physical world, how often do you lose your house or car keys? I can't remember if I've ever lost them for good and had to pay a locksmith. It just doesn't happen. I do have a spare of each key (or another type of key like a garage door opener) I'm case it does happen. Why does everyone bring up the problem of lost keys when it comes to computers? It's no t that big of a deal. I know I've lost or forgotten far more passwords than I have physical keys over the course of my life. Am I that different from the average person?