Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

With a sufficiently programmable hardware key, yes, you can back up the secrets. See an enumeration of methods in [0]. Be careful if you plan on doing this; make sure the tradeoffs make sense to you. You probably want to do the programming from an airgapped, trustworthy Linux machine.

Beware that if you do this and lose your primary key, or if it is stolen, then an attacker can impersonate you. Setting up multiple unique keys is probably more useful in general, even if it's more cumbersome.

[0]: https://dmitryfrank.com/articles/backup_u2f_token



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: