Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Thanks. I have quite a few services that only let me register one key. I always worry that if I lose my phone (or break it) I am going to be locked out.


Are you sure? I think you might be confusing OTP codes (what you get from an authenticator app on a phone) with U2F (a device like this that communicates via USB or NFC). Most services I know of only support one OTP seed (you can use it with multiple devices, though - just scan the QR code with all of them, the entire secrets are encoded in it. Of course, this makes it very cumbersome to add or remove a device, as you have to re-enrol all of them). But only allowing one U2F token is a bad idea, as losing (or breaking, depending on construction) it is very easy.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: