Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I definitely would like the requirement to allow multiple keys to be a part of the standard. Allowing it at the key level seems dangerous to me, perhaps, in allowing an attacker to perhaps "clone" someone's key that hasn't setup a pair yet, though of course I'm sure there's mitigations for that if it was seriously proposed!

I have two Yubikeys, one in a safe and one on my person. It saved my butt when I lost access to the one on my person for a few days!



The fido2 protocol involves a counter that allows the server to detect cloning of a device :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: