Backup 2FA methjod
Brought to you by:
jeffharris
A big problem with 2FA using a Yubikey is that the device would have to be carried all the time. Things you carry all the time, like keychains, get lost or broken. Being locked out of an important password file would be a serious problem.
Is there already a method to have a fallback 2FA device, such as a 2nd Yubikey?
If not, consider this a feature request.
Anonymous
A simple way to implement a fallback would be to maintain a backup file saved against the second FIDO device.
I believe the Yubikey manager for the PC has a method to backup and/or duplicate a Yubikey. See https://pwsafe.org/help/pwsafeEN/html/manage_menu.html#%23yubikey in the instructions for setting-up a Yubikey for Password Safe.
Management of Yubikey devices is left to the PC Password Safe and/or Yubikey applications