Hacker News new | past | comments | ask | show | jobs | submit login

To Github people: I ordered your yubikey token but stayed away from U2F out of fear that I'd be locked out if I lost the hardware token.

But I didn't realize you could setup U2F and TOTP as a backup.




Not only can you do this, but the major services won't even let you set up U2F without a backup factor.

The best current Google auth stack, by the way, is:

1. U2F

2. Phone-based authenticator app (TOTP)

3. Password-manager password

4. Printed codes

5. DISABLE SMS. (Google forces you to enroll in SMS to turn on 2FA; you can simply delete your phone number after enrolling everything else).


Thank you for letting me know that SMS authentication is not mandatory for Google accounts! I assumed it was for the reason mentioned in your comment.


For some reason I made the wrong assumptions. Thanks for the clarification. I'm going to activate that U2F key asap, and also disable SMS for my google account.


You can also order as many of the U2F devices as you wish and associate them all with any number of accounts. Yes, they do cost money, but the cheapest today is $10 shipped on Amazon. Even if you prefer the ergonomics of the more expensive ones, it's fine as a backup you keep locked in a safe at home.


I do this, but the downside is, if I lose one I have to go through each service removing both tokens (because some services do not tell you which is which) then adding the existing (not lost) token with the new one. This is making me wish for OpenID again where I nominate my authenticator of choice so I only have one place I need to maintain my tokens.




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: