Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You don't need $50 products. You especially don't need two of them.

Yubico already make a Security Key that isn't also a PGP key store, a TOTP authenticator, bagel toaster and whatever else for about $20. And there are cheaper vendors if price is the main concern.



The $20 one doesn't support a phone, regrettably. We need at least the $45 NFC edition, or it won't help people trying to log in with their phones. We continually talk on HN about how many are increasingly only using their phones and no longer use or posses general purpose computing devices. A USB-A only device only works for people still using computers. The Mobile Authentication Taskforce still wins and your only choice anywhere that isn't already highly technical will end up being Project Verify and the point of failure will still remain as socially engineering underpaid customer support staff.


Why do you say you don’t need two?

The argument seems pretty straightforward: if you don’t trust SMS, you need to disable all backup authentication. If you’ve disabled backup, you surely don’t your physical device to be a single point of failure?


My point was that your backup "emergency" token doesn't need all the fancy features of the 5 series.

It's the backup option, it's the reserve, it didn't have to be the best possible thing, just enough to get you back into the game after you lose the main token somehow.


You don't have to use sms as your backup authentication mechanism. TOTP and 1 time use codes are both better options.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: