logoalt Hacker News

EvanAndersonyesterday at 8:16 PM1 replyview on HN

Speaking about hardware tokens:

If I have to go get the backup out of "secure" storage each time I want to add a new Passkey it's not really a backup.

The design should have allowed, even if it was just within only the purview of a single manufacturer, a method for the device to export an encrypted dump that could be reloaded onto a factory-new device. Heck, make it a value-added service that the manufacturer has to initiate and tie it to some real-world identity verification.

The idea of having to put backup devices in-hand regularly is a bad design.

Phone apps. get around this idiocy by backing-up the encrypted Passkeys to a hosted service.


Replies

pseudalopexyesterday at 9:40 PM

> If I have to go get the backup out of "secure" storage each time I want to add a new Passkey it's not really a backup.

Yes.

> even if it was just within only the purview of a single manufacturer

> Heck, make it a value-added service that the manufacturer has to initiate and tie it to some real-world identity verification.

No.