Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's a great plan, but AWS notably doesn't support multiple hardware u2f devices.

They've been sitting on the ask for about 7 years

https://forums.aws.amazon.com/thread.jspa?threadID=137055



Don't they have 2FA recovery codes?

This had become somewhat of the standard for 2FA in recent years.


Can you not manually set the two tokens to the same "seed"?


That works for TOTP 2FA on your phone. But most hardware tokens have an internal seed that's immutable.


Isn't that just the enterprise ones? I've been using personal hardware TOTP tokens[1][2] like this for years, where you can set the seed yourself using NFC.

[1] https://www.token2.com/shop/category/programmable-tokens

[2] https://www.protectimus.com/protectimus-slim-mini


The problem with totp is it's really just a second password. It eg doesn't protect you from phishing in the way that a yubikey does.


I think they meant hardware in the sense of U2F tokens like Yubikeys, not TOTP based ones.


Damn, that sucks. I use GSuite to SSO to AWS though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: