2FA by hardware key only
Being able to add physical Fido token is great but I would like that the requirement for TOTP to be removed.
TOTO is quite often software based and software = surface of attack. Physical token allow air gap and are very secure and I don’t need TOTP personally, it makes my account vulnerable.
Also just like Apple, a minimum of 2 physical tokens should be enforced since having a single token is putting you at risk of you loose it. 2 or more should be the rule of thumb.
16
votes
-
Asif Charfare
commented
I agree. Please add hardware key as an option without requiring an authenticator app. 2 no. keys minimum to ensure backup.