• Appoxo@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    1
    ·
    8 hours ago

    Can it be copied from your phone? (e.g. by migrating your phone via a backup)
    Then it can be compromitted and is essentially a single factor (because some website permit you to login via the key only).
    Only if you’d need to completetly renew the key, then it’s truly secure.

    • ricecake@sh.itjust.works
      link
      fedilink
      arrow-up
      1
      ·
      2 hours ago

      There are secure ways to transfer the key that preserve the properties that make it useful as two factors in one.

      Basically, the device will only release the key in an encrypted fashion readable by another device able to make the same guarantees, after the user has used that device to authenticate to the first device using the key being transferred.
      A backup works the same way.