Allow registering multiple security keys in MFA
Currently, only a single security key can be registered as an MFA device. As a backup to this key, only other mechanisms such as authenticator apps can be used. It would be nice if multiple keys could be registered to avoid having to use a different method as the backup.
10
votes
Johannes
shared this idea
-
Juan commented
The current implementation is terrible - whoever decided to allow only one security key should have their head examined.
-
(Admin) B commented
This is quite important as a single security key is a single point of failure; using a weaker backup option weakens the whole MFA. Witness the recent attacks on Cisco and Cloudflare: Cisco got owned as their staff were using OTPs, Cloudflare didn't as they use security keys *only*.