Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think password managers are the first step you should take and FIDO/U2F hardware keys are the second similar important step.

With that even if your password manager get hacked you still have a secure account as they didn't got the U2F at the same time a password manager is a must have as it's prevents a lot of phishing attacks from even getting any chance and is quite convenient, too.

The problem with hardware keys is that for many people they are not so easy:

- You MUST generate and safely store recovery keys, storing them in your password manager is suboptimal, but better then not having them. (Not having them means potentially losing account access permanently.)

- You often need to enable it.

- You should store it with your keys, which dependent on habit might not be around your PC (in my case they always are in my pocket so :=) ).

- If your site doesn't support U2F/FIDO you might need an additional phone + app, or laptop app to get the numbers out of your key.

So while I think it's a must have for every developer to have a hardware security token lie a Yubikey it's not something I could convince e.g. my Dad or Sisters to use.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: