Conversation

I learned the other day that FIDO2 keys have a counter so that if an attacker does manage to clone the key, and both keys continue to be used, the counter for them will desync and the server can detect the clone. Pretty cool, wonder how that plays out in practice.
3
11
Like I'm pretty sure the recommendation is allow for two keys but AWS still doesn't, so I'm a bit doubtful that the average backend is detecting/ handing this, but I'm certainly curious to hear otherwise.
2
2
Show replies
Replying to and
Most sites don't even allow you to have security keys as the only 2FA mechanism. My Google account is opted into the Advanced Protection Program so it's the only option. It's quite important since it's my domain registrar and OVH recovery email.
1
Show replies