Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've yet to see an answer to the elephant in the room: if your phone gets lost or bricked, what's the recovery path?


Typically you set up many devices that can be used for authentication - your android phone and windows desktop, as well as a USB key in your safe for emergency access into bank accounts and the like.

Account recovery is a pretty well-known space as well. If the person does not have any authentication mechanisms left, you can send an email link or go through identity proofing depending on your security requirements.


And then banks will decide that it's not secure having multiple devices and actively prevent you from doing that.

Right now my bank requires my phone to get a 2fa code for anything important. I can only have a single device at a time, if I lose my phone, I can of course reset it if I'm in the country and go to a branch. Of course with Covid that was difficult when I last lost my phone, so I had to download a form sign it and fax it to be able to set up my 2fa on my new phone. It took 2 weeks before I could access my bank account.


> And then banks will decide that it's not secure having multiple devices and actively prevent you from doing that.

IMHO based on current policies, it is more likely that they will have one device on your account, like a combined USB and NFC hardware authenticator, that you can request from them and becomes expected for higher security interactions like large money transfers.


If you count that as part of phone-as-password cure, that makes the cure worse than the disease, in my opinion. Now I need to maintain and regularly test a recovery path. (Much like backups, if you don't test them, you literally don't even know they work. Other device needs good working order, perhaps subject to OS patching and data loss--pay attention, or your supposed backup plan might not work at all)


In the article. Cloud rsync of fido state, PKCS wrapped for the security concious.

Our fallback on passphrase held off-line, for emergency use only.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: