Quote:
Originally Posted by GoinAllTheWay
Hopefully have MFA turned on for LP too.
I've really got to get off the app based MFA, anyone here using Yubikey? I've heard mixed reviews with them but as far as I can tell, it's the best form of MFA you can get atm.
|
Yes. Yubikey FTW!
I do use them in a few different manners:
- with the Yubico Authenticator ("YA")....so several copies of YA on phones, PCs wherever and multiple Yubikeys ("YK") all "recognized" by YA. So, if I lose a phone or a PC craps out ANY OTHER YA will still work. Essentially these back up each other as they are redundant copies.
- in Windows Hello....MUST insert a YK to boot to OS. If no key...no access to the (encrypted of course) OS.
- as a sole identifier: so, if adding (say) 1Password to a new machine, not only do I need to supply the various requirements of 1P, but the 2FA from a YK as well in order to install it and make it effective.
When we travel, my wife has a spare YK that can access everything on her key ring in case one of my usual copies gets lost. As well....a backup at a secure location of course.
Can be a bit confusing at times, but worth the effort in the learning curve.
Start with things that "don't matter" in order to test.