upvote
Just have the 2nd device when you create any account. But have it away from the 1st device always. Just update 10s or 100s of accounts for every new device. Just never use sites which allows 1 Passkey.
reply
Speaking about hardware tokens:

If I have to go get the backup out of "secure" storage each time I want to add a new Passkey it's not really a backup.

The design should have allowed, even if it was just within only the purview of a single manufacturer, a method for the device to export an encrypted dump that could be reloaded onto a factory-new device. Heck, make it a value-added service that the manufacturer has to initiate and tie it to some real-world identity verification.

The idea of having to put backup devices in-hand regularly is a bad design.

Phone apps. get around this idiocy by backing-up the encrypted Passkeys to a hosted service.

reply