Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can instead opt to use HSMs for your Apple ID MFA. I have 3x YubiKeys in various locations for this exact purpose.

https://support.apple.com/en-gb/HT213154



They mention "FIDO® Certified* security keys", this presumably means physical keys only, and not soft keys like the ones that keepassxc/bitwarden provides? If so that might be too much of a hassle for me. I care about my security, but I don't care enough to drop $100 on 3 separate security keys, and finding 3 separate places to keep them secure.


You need two keys, not three.

But yes I wish you could use one hardware key as backup and one software key for day-to-day usage, or at least the security key in a trusted device (up to you to have a circular dependency to your main device or not).


It does not help you when a trusted device is stolen, the yubikeys can be disabled if they unlock your phone or device




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: