[Discuss] Password managers

Daniel Barrett dbarrett at blazemonger.com
Wed May 6 15:30:03 EDT 2020


On May 6, 2020, Kent Borg wrote:
>Yubikey feels more "Isn't this cool!?" to me than it feels secure.
>Why should I trust it will only let me in? Why should I trust it
>*will* let me in?

True, it's a black box, but it's a black box that world-class security
professionals have trusted:

  https://www.yubico.com/about/reference-customers/google/

  https://www.theverge.com/2019/10/14/20913456/google-titan-usb-c-security-key-yubico-yubikey-nfc-bluetooth-fido-os-compatibility

>What the hell do I do if I damage it? Exactly how screwed am I?

Fortunately, not screwed. Every site that supports Yubikey, at least
that I've seen, provides one-time backup codes in case your key is
unavailable.

Also, you can have multiple, distinct Yubikeys and keep one in a safety
deposit box.

--
Dan Barrett
dbarrett at blazemonger.com



More information about the Discuss mailing list