Allow registering multiple security keys in MFA
Currently, only a single security key can be registered as an MFA device. As a backup to this key, only other mechanisms such as authenticator apps can be used. It would be nice if multiple keys could be registered to avoid having to use a different method as the backup.
10
votes
![](https://secure.gravatar.com/avatar/9f320621d393e49c9766bc8bc81034d9?size=40&default=https%3A%2F%2Fassets.uvcdn.com%2Fpkg%2Fadmin%2Ficons%2Fuser_70-6bcf9e08938533adb9bac95c3e487cb2a6d4a32f890ca6fdc82e3072e0ea0368.png)
-
Juan commented
The current implementation is terrible - whoever decided to allow only one security key should have their head examined.
-
(Admin) B commented
This is quite important as a single security key is a single point of failure; using a weaker backup option weakens the whole MFA. Witness the recent attacks on Cisco and Cloudflare: Cisco got owned as their staff were using OTPs, Cloudflare didn't as they use security keys *only*.