• HotChickenFeet@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    3
    ·
    23 hours ago

    Im not terribly familiar with the HW keys; Are you able to get multiple keys? I would worry that it would be similar to TOTP, in that if you lose/misplace/don’t have the device then you would be locked out.

    And I probably wouldn’t switch banks for it, it would depend on how much more secure I perceived it and any other bank differences.

    • brie@programming.dev
      link
      fedilink
      English
      arrow-up
      2
      ·
      23 hours ago

      Yes, you can have multiple devices with the same seed for the pseudorandom number generator. You can turn any computer into a hardware authenticator. In practice, it depends on the bank or your employer. Google reduced phishing success rate to zero after switching to ubikey.

      As for perception, you really nailed it. It’s more important than actual difficulty of gaining access to your accounts. Remember that most articles are written by low skill blue teamers who manipulate your perception into thinking it’s really easy while they don’t possess the skills to do it. Always call them out in a manner like “you claim it’s easy, have you done it?”. They will always say no.