Comment on More than $35 million has been stolen from over 150 victims since December — ‘nearly every victim’ was a LastPass user

<- View Parent
Rootiest@lemm.ee ⁨1⁩ ⁨year⁩ ago

Having a recovery process for the YubiKey world really just be a potential security hole.

Ideally you have a backup clone of the key in case yours is lost/broken.

Keeping a recovery seed or backup password instead would be inherently less secure as the YubiKey uses an HMAC challenge-response key for KeePass rather than a static password/key file.

A static password or key would be a better target for hackers as it would be easier to crack so having that option would lower your overall security.

source
Sort:hotnewtop