> Google prompts
> "To stop getting prompts on a particular phone, sign out of that phone."
Well, f* you too.
I genuinely hate this idiotic future where I'm not given a choice.
I have a yubikey, a TOTP, and backup codes. Leave my phone out of this.
> Google prompts
> "To stop getting prompts on a particular phone, sign out of that phone."
Well, f* you too.
I genuinely hate this idiotic future where I'm not given a choice.
I have a yubikey, a TOTP, and backup codes. Leave my phone out of this.
To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup codes would stop working, as would any third-party apps that need access to data in your Google account.
The YubiKey, by the way, is a great hardware TOTP key, in addition to being a FIDO U2F key. TOTP has an advantage over U2F in that you can keep backup copies of the TOTP secrets. Of course TOTP is less secure because it is phishable, but U2F is a real pain because you can't make backup copies of the key.
Dogma: If it isn't backed up then it doesn't exist.
For real backup resiliency, you should have at least 3 keys, one of which you keep off-site. Presumably you keep one at home and one with you. Want to sign up for a new service? I hope you're at home where you can access two of your keys to register them. Then sometime later you need to go to your off-site location to swap that key, bring it home, and get it registered also. Do that periodically so all of your services are on all 3 keys.
Unclonable hardware keys work well enough when it's for a corporate service. Lose the key? Just visit IT and have them give you a new one or overnight it. But unclonable hardware keys are a huge pain when used personally with multiple services.
TOTP secrets, while less secure, are much easier to manage. You can write them down, store them on a USB stick, or store them in an online account. You can send them in a message or even read them over the phone. Ultimately the average user is more concerned about losing access to their account than being attacked by a nation state.
Don't you have a second authentication factor to login on your phone? Fingerprint, pin, faceId.
I don't see how this is worse than a yubikey.
The backup is to have multiple U2F keys. I have over 10 U2F keys. Most (but not all) providers allow you to register multiple U2F keys.
Amazon AWS for some foolish reason (in my opinion) is one of those outliers which only allows one U2F keys to be registered. I've read people's reasoning on why that is and none of it makes sense to me.
Can you walk me through your workflow with these? Are some stored offsite? Do you have to gather all your keys together when you are signing up for a new service with U2F support?
I have 4 main ones that I try to keep synced with every service. Though I usually try to sync up a few more if I have them handy.
For me those four are:
Laptop (Yubikey 5C Nano) Desktop #1 (Youbikey 5 Nano) Desktop #2 (Yubikey 4 Nano) Keychain (Yubikey 5 NFC)
I also have one in my work-laptop but it is only registered for work related sites. I also register some of the previously mentioned ones for my work related sites as a backup.
The basic idea is to have two U2F devices with with the same device_secret but one of the devices (the backup) is pre-programmed to add a large offset to the so called counter value. Upon login the service must check the counter value and ensure that the received value is greater than the one it's seen previously. If you happen to lose the first key, you can use the second key to log into all of the affected online services and upon doing so, the service would accept the new larger counter value and thereby invalidate the lost key.
Seems like they prefer google prompt, then SMS, then the actually secure stuff.
So whatever you're seeing is not in fact some sort of Google policy to prefer insecure SMS.