Here's a guide on how to implement 2FA that paypal followed along nicely:
First step: enforce the use of an authenticater app as a backup method, with no other way around it.
Step 2: allow the user to then add *only* ONE physical security key, because who'd need two of them anyway? One of the fundamental ideas behind having physical security tokens is to have at minimum two of them in the first place, but never you mind.
step 3: confirm that the key has been added to the user's account, get rid of the add security device button
step 4: tell the user they can now log in with their security key.
The result? You're using a security key that's not registered with this website.
Log in with your authenticater app or passkey, because why not use that instead? Go into settings and confirm that your security key is actually present and that paypal just decided to be a complete idiot.

#2FA #epic #fail #securitykey #twofactorauth #wtf

How To Setup A YubiKey Security Key As A Passkey To Sign In To Online Accounts, e.g. Google Account

YouTube
How To Safely Eject And Remove A YubiKey Or Any USB Device On Windows

YouTube
How To Test And Verify If your YubiKey Is Genuine And Functioning As Designed

YouTube

Hardware keys are the gold standard for MFA — our latest guide breaks down the best security keys and how to use them. Read more: https://wix.to/KYgRL1o

#MFA
#SecurityKey
#InfoSec
#Privacy

Top-Rated Security Keys: A Deep Dive into Hardware Authentication

Discover the best Security Key for multi-factor authentication in our comprehensive guide. Enhance your digital safety with the right Security Key.

Oz

Xa temos en  dispoñible a versión 1.2.1 de #AuthnKey (provedor de claves de paso e chaves de seguridade para  ). É a primeira co idioma #galego incluído 

Polo mesmo prezo 💶💶 traducín Open Passkey Authenticator (a día de hoxe aínda non se publicou en galego).

#android #passkey #securitykey #authenticator #token2 #yubikey et al.

#yubikey #passkeys #securitykey What is the rationale for forcing me to register my yubikey as a security key (WebAuthn) TWICE for a website?

1: Ubuntu Linux
2: Microsoft Windows

I have had my Yubikey for 2FA work for years without a hitch using Linux, but as soon as I move to Windows, I have to register it on the website again or be hit in the face with "This security key doesn't look familiar" with no suggestion to i.e. enroll it (again)!

👀 I’m part of the 0.5% Twitter’s users that# use a #SecurityKey for 2FA. Do we know how much people are using this feat#ure in #mastodon ? From: @SpyBlog https://mastodon.social/@SpyBlog/109884411127070890 [Originally posted: 2023-02-18 07:20 UTC]

Joost van Dijk from @yubico tells us about #OpenSSH combined with the #FIDO standard at the @nluug #najaarsconferentie. This info applies on any FIDO #securitykey, not just #yubikey.

#opensourceconference #Linuxconference #conference #conferentie #NLUUG #nluug25nj #hardwarekey