Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Additionally, if somebody removes the token, dumps a bunch of OTPs and then puts it back, as soon as you use the token once, it will invalidate all previous ones so their dump will be reasonably useless. I leave my key in my computer when I'm at my desk but have it attached to my keychain so that I take it with me if I leave my desk.


FYI the nice thing with security keys, is that you can't actually do that (dump a bunch of OTPs to use later).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: