Hacker News new | past | comments | ask | show | jobs | submit login

Every place that I use my key gives you a set of one-time-use recovery codes. To log into your account, you can use either the key or a code. (You still need your password.) Codes can be regenerated at any time. To revoke a key, you simply remove it from your account.



You have to make sure the attacker cannot revoke your key first. If the backup code is unrevokable, then it is indeed a nice solution, albeit a high-friction one if you are doing safe backups for each new account.


Can you give a list of all these places?

Gandi doesn't even have a non-human method of recovery.


Facebook, Google, Dropbox, and github, at least.


Fastmail also.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: