Why am I only allowed to create one security device for 2 factor authentication?

bpip
Contributor
Contributor

I want to utilize TWO Yubikeys so that I have a backup incase one is lost/stolen/breaks/etc. This is a VERY standard practice when using physical security devices like Yubikeys and as far as I've found, PayPal is the only service I'm using at the moment that hasn't allowed me to pair a a second YubiKey with my login for 2 factor authentication means. 

Am I missing something? Is there in fact a way to utilize a second key? I click on "add new device" just like before, but now I'm only presented the option of adding a phone number for SMS verification instead of the ability to pair a second physical security device... 

Login to Me Too
47 REPLIES 47

MattTheTechLV
Member
Member

Come On Paypal, Fix this! We should be able to add AT LEAST TWO FIDO2 Keys to our account, realistically you shouldn't limit the number of Hardware Security Keys at All, but allowing us at least One Backup is the Secure way to implement this. Come on Paypal...

Login to Me Too

GregSteuck
Member
Member

Like the rest of the commenters I'm puzzled by this choice to implement support for only one security key. I don't know of a single other place which imposes this kind of restriction. It is really quite inconvenient because I have multiple security keys, not to mention the fact the phones contain similar security elements.

 

The first security key took 10 years to implement since they became supported by Google. Would it be reasonable to assume that it will take 10 more years to get the second one?

Login to Me Too

untwistedapple
New Community Member

I don't understand why PayPal is restricting this. As well as using a key in their app. When I use the browser of my phone, PayPal accepts the key! What the hell?

Login to Me Too

LDWilliams
Contributor
Contributor

It seems stupid to me that PayPal harp on about security and then HINDER us from doing exactly That!

Login to Me Too

mrmizer
Member
Member

Well it's 2024 and they still haven't fixed this issue. Obviously they DON'T CARE!!!!!! Like it has been said, this is too stupid to put into words.

 

Yubico should drop Paypal from their support list for violating one of their primary rules - have two keys.

Login to Me Too

atketki3
Contributor
Contributor

et42
Member
Member

In the past I used Paypal very frequently particularly in places where I wanted to have the highest possible level of security. To me it looks like Paypal completely messed up implementing the new security standards (FIDO2, Webauthn) and also providing a very unconvenient functionality in their app (having to provide a TOTP even after having authenticated via biometrics is just completely stupid!). And Paypal was among the initiators of the FIDO2 standard! I cannot understand their behavior. The only explanation I have is that they actually don't care for their user's security.

 

If a service does not meet your expectations anymore, you find a better one, correct? Thus, I plan to move away from Paypal wherever possible as I don't trust them anymore. What alternative services are you using to replace Paypal?

Login to Me Too

joravasal
Member
Member

What a bad look for paypal...
A payment service that won't fix issues with security...
2 years after the post and still no official answer or intention to fix this.

Nice......

Login to Me Too

Haven't Found your Answer?

It happens. Hit the "Login to Ask the community" button to create a question for the PayPal community.