Hacker News new | past | comments | ask | show | jobs | submit login

Damn. I wonder if I can emulate a USB host on the other end and put a USB device such as a Yubikey "in the cloud" so that multiple devices can use it as a U2F device.



Sounds possible, but wouldn't that defeat the purpose of the yubikey, or at least undermine it?


Yes, but the problem is many websites have horribly shitty implementations of 2FA notably AWS, PayPal, Kraken, Gusto among others. All of these websites only permit registering one key instead of multiple.

You're supposed to allow multiple keys so that if one key gets lost or stolen, you can login with another one and deactivate the lost key, among other reasons.

I also generally leave a key in each of my frequently-used devices and don't like to move keys around or travel with keys, especially on the streets of San Francisco. I have a computer at work, a computer at home, and don't want to commute with a laptop considering 3 friends have been mugged in just the past week.

So for these I'd rather circumvent the 2FA by putting the key in the cloud until they hire some better engineers who can implement multi-key 2FA.


You might be able to use something like VirtualHere or USBIP for sharing a remote USB device over network




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: