Best solution would probably be an implant of the physical key which makes it nearly impossible to lose it (apart from the worst case scenario).
Best solution would probably be an implant of the physical key which makes it nearly impossible to lose it (apart from the worst case scenario).
EDIT: How to register your spare Yubikey: https://support.yubico.com/hc/en-us/articles/360021919459
I thought the idea was that we’d write the secret once to an arbitrary number of primary and backup devices, then destroy it so it can’t be stolen as easily. Although I guess password managers save TOTP secrets alongside the password factor these days too.
Does the “the secret itself is not phishable” aspect of TOTP just not actually matter in practice as much as the rapid expiration and frustrating replay attacks / on-the-wire sort of secret interception?
The concept that if I lose my key I am totally screwed doesn’t align.
Notary public... the new digital locksmith for password recovery.
So in the end she was locked out of the encrypted backups and had to wipe the phone, losing photos and a lot of notes. Despite all this, somehow expected that a quick ring to the <Cell Provider> call center could get her files unlocked and restored. Once that proved fruitless, that a call to Google would do the trick.