<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=4&amp;t=597" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2010-11-17T16:07:19+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=4&amp;t=597</id>
<entry>
<author><name><![CDATA[JoelKatz]]></name></author>
<updated>2010-11-17T16:07:19+01:00</updated>
<published>2010-11-17T16:07:19+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=597&amp;p=2447#p2447</id>
<link href="https://forum.yubico.com/viewtopic.php?t=597&amp;p=2447#p2447"/>
<title type="html"><![CDATA[Suggestion: Simple tweak to online authentication servers]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=597&amp;p=2447#p2447"><![CDATA[
A lot of people have asked about the ability to support multiple or backup Yubikeys. This is actually trivial to do, requiring only a tiny change in the servers and no change in the clients. Simply change the validation servers to track the insertion and OTP counters on a per-private-ID basis.<br /><br />Then, you could program multiple Yubikeys with the same public ID and AES key but different private IDs. This would permit a simple backup/spare Yubikey mechanism. You could have one on your keychain, one at home, one at the office, and so on.<br /><br />The personalization tool could easily be modified to allow you to insert any number of Yubikeys and it would simply program each one with a different private ID.<br /><br />If you want to get fancy, a web page could be provided to associate a 'nickname' with each Yubikey. You just insert a Yubikey, generate an OTP, and enter a nickname, like 'Office' or 'Keychain'. The web interface could permit a lost Yubikey to be disabled simply by bumping the counter for that private ID to the maximum permissible value. (No OTP with a greater count than that can possibly be generated.)<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1449">JoelKatz</a> — Wed Nov 17, 2010 4:07 pm</p><hr />
]]></content>
</entry>
</feed>