logoalt Hacker News

avh02yesterday at 4:56 PM2 repliesview on HN

The problem here is i want to have more than 1 yubikey, so if i lose it, all is not lost... I can't do that with the current implementations unless i present N yubikeys to every new account i make. Which makes an off-site backup yubikey impossible. With my current yubikey usage with password store, my "offline" yubikey can be brought in whenever i want to decrypt the passwords, including ones inserted while the key was in storage.

Also yubikeys have limited passkey slots (100, 25 with old firmware)


Replies

pllbnkyesterday at 5:21 PM

Also, where do I store the backup Yubikey, or any other pass key owning device for that matter? It has to be easily accessible to set up the pass keys, but also safe from accidents like house fire.

There's a strange tension where I want to use pass keys because they are easy to use but also they are easy to lose, so I choose a KeePass synced over cloud and deal with a bit of a hassle by having to copy/paste my passwords.

preisschildyesterday at 6:30 PM

I think technically you can just register the public key of the passkey and only need it on-hand for login

show 1 reply