TOTP (and other) secrets will never come out of a Yubikey once they've been sent into it. And I like it that way.
TOTP (and other) secrets will never come out of a Yubikey once they've been sent into it. And I like it that way.
It's not possible to clone yubikeys
https://support.yubico.com/hc/en-us/articles/360016614880-Ca...
Look at the "few exceptions" section
So one strategy for maintaining multiple authenticators or yubikeys would be to save all the secrets away and call them up when it's time to load up the alternate factor.
What I do is register both keys at the same time, one after the other so the QR code doesn't leave my screen. Can't do it this way if the one key is in cold storage, of course.
If you're referring to the Unix tool "dd" the answer is unambiguously no; zen_1 misunderstood you.
No data comes out of the Yubikey except answers to the cryptographic queries. There's no storage to dd.
The only way to clone secrets is to grab them before they go in and save them elsewhere. That's what we mean by "time of setup" or "time of programming" is when putting a new secret in, not like initial setup of the device.