| ▲ | lxgr 3 hours ago | |||||||||||||||||||||||||||||||
Enrolling two devices stored in different locations for every sign up is extremely annoying. I suspect that most people that ostensibly do this actually only enroll one for non-critical accounts and then depend on some fallback mechanism. | ||||||||||||||||||||||||||||||||
| ▲ | iamnothere 3 hours ago | parent [-] | |||||||||||||||||||||||||||||||
This is a legitimate problem, and one of the few cases where a third party login provider makes sense, at least for non-critical “apps”. If both tokens can be authorized to that provider, then you don’t need to enroll any more tokens for apps using that provider. The difficulty is creating a trustworthy provider system without weakening security (the provider shouldn’t be able to login without you) that doesn’t collect information about you and which can’t lock you out from all your accounts. I’m not sure what work has been done on this since Mozilla Persona. I certainly wouldn’t want Google and Apple, or governments, to be the sole gatekeepers. | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||