Yes.Trying to get my head around this... So how does the implementation of this work with Apple devices? Say I have an iPad, an iPhone, two MacBooks. I access an apple service (on any device) that would normally send me a 6 digit TOTP. Do I then instead of the code get prompted to insert or tap the physical key?
As I understand, there's no fallback to another 2FA method. If you lose both physical keys you'll have to use either a recovery code (which you hopefully have generated in advance and stored in a safe place) or a recovery contact (i.e. a trusted friend).And if I don't have the physical key with me or nearby, how do I fall back to another 2fa method?
I only like them if the device and the app/site I am on autofills it. The one that bugs is actually Apple's stuff. If I get the code on Android, they have those dumb boxes, so it only fills the first number.Can't come soon enough. Does anyone actually enjoy getting 6 digit SMS messages?
Yea most or all of the Auth apps I've used give like eight recovery codes you need to save somewhere. I don't know how physical ones work because I never used one. Do they have a paper with codes, or can you go on a site to get them?Yes.
As I understand, there's no fallback to another 2FA method. If you lose both physical keys you'll have to use either a recovery code (which you hopefully have generated in advance and stored in a safe place) or a recovery contact (i.e. a trusted friend).
Yea just hope the physical key is 1 priority. Wish you could set the order. My SE is backup now and is just at home. If I want to check the card or icloud on my Android, I always have to tap multiple times to get the SMS. There needs to be a way to set SMS as 1 priorityI hope not, bit rather take priorities.
what if the physical key is lost Or damaged?
permanently lock yourself out of account?
You need one key that's always with you (on a key ring, or in your wallet, or something like that), or at least within reach, and one that's stored safely at home or in some other secure location.that would require buying a key for every device or moving one key around constantly.
The watch will be fine, as it doesn't connect to iCloud directly. It's paired to a phone, which in turn is connected to iCloud. So, it's the phone that will need the key, not the watch.And what of devices like Apple Watch?
Actually cellular Apple Watches I'd assume *do* connect to iCloud directly as they work independently of the iPhone, however I accept one is unlikely to be doing much on a watch that would require that level of authentication.The watch will be fine, as it doesn't connect to iCloud directly.
Good point. I forgot about those, because all Apple Watches in my family are wi-fi only. 😊Actually cellular Apple Watches I'd assume *do* connect to iCloud directly as they work independently of the iPhone
Not sure you ever got a response, but I used my blue Security Key as one of the two I registered this morning without issue. My other key was a 5C NFC.Has anyone tried the beta by adding an NFC Security Key (the blue one)?
I wanted to buy two for a good price just to use them with my iCloud account.
Are they okay or do I have to buy the YubiKey 5 Series?