Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But it's always possible to get a new passport, even if you've lost every other type of identification. What happens if I loose my Yubikey and all of my backup codes?


As noted in the article, it's a tough problem. The easier you make account recovery the easier you make attacking those recovery methods.


It so happens that I have a great solution to this tough problem, which has served me well for years.

I have a password manager, protected by a strong, unique, randomly-generated master password that I took the time to commit to memory. I cannot ever loose this password, and as long as I have it, I can get into my vault. As long as I can get into my vault, I have access to my other passwords.

An increasing number of web services have decided this is insecure, and are forcing me to use secondary devices in order to authenticate myself. This does very little to increase my security, while putting me at risk of getting locked out of essential resources.

I'm all for alternate options, but please don't take this setup away from me!




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: