So we should all be demanding that systems which require hardware 2FA don't *also* require keys which are generated at/by the manufacturer, right?
So users should be able to upload their own keys to the device, right?
Because otherwise that's a supply chain vulnerability, right?

"But Christine, that means some users might actually use software encryption systems for 2FA instead of hardware keys"

Okay, let them... let the user make that choice

Like seriously, otherwise you're opening a nation-state level attacker, or even just a manufacturer that *doesn't* happen to have your interests in mind, the possibility of backdooring like, everyone who's required to use these.

Hardware keys where the private key can't be pulled off them can be useful, *assuming* users can upload their own keys to them.

Oh right, there's a whole other different reason I'm interested in being able to upload my own key: I'd like to have a backup (encrypted itself and left in a secure location with something like paperkey) so I don't lose access to my digital life.

Lockout dependency cycles suck, and people are experiencing them: shkspr.mobi/blog/2022/06/ive-l

Follow

@cwebber you don't need an exact copy of the key, you need a bunch of peer keys

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.