• Clegg@lemmy.ca
        link
        fedilink
        arrow-up
        2
        ·
        11 months ago

        Same. I had high hopes but I find it less convenient than other 2FA methods.

        • FlappyBubble@lemmy.ml
          link
          fedilink
          arrow-up
          2
          ·
          11 months ago

          Why? You can have it constantly plugged in and just touch it to login.

          My favourite use is to secure SSH with it.

      • linearchaos@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        11 months ago

        Mine sits on my keys waiting for me to use my banking app or password manager from a new device. Sure for everyday crap like Facebook TOTP is fine.

        If you’re picky and choosey about what uses the yuppie key it becomes a lot more useful and less annoying.

    • cooopsspace@infosec.pub
      link
      fedilink
      English
      arrow-up
      2
      ·
      11 months ago

      Minimum two, preferably three.

      The second one is for backup purposes.

      The third one is to go in your safe.

      • KrisND@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        11 months ago

        Agreed. But the 3rd one I might put in a different geological location…that is if something already happened to 1&2…

        • cooopsspace@infosec.pub
          link
          fedilink
          English
          arrow-up
          1
          ·
          11 months ago

          The challenge with the keys is you need to set them up on every account and each key. So you can’t have your recovery key that far away.

          But merely as a backup key for your password manager, fine.

          Most of my stuff runs OIDC and on my home server, so if my whole house gets washed away I have more problems than a lost key.

    • Noughmad@programming.dev
      link
      fedilink
      arrow-up
      1
      ·
      11 months ago

      I only use it because my job mandates it. They allow us to use the same key for private stuff, but it’s just too inconvenient.