Cut the Clutter: Test Ignore Files Feature - sign up to become a beta tester here.

Forum Discussion

bhagmeister's avatar
bhagmeister
Explorer | Level 3
3 years ago

How to select Hardware Token (key) as primary 2FA method

Just registered two Yubikeys. However, when logging back in to the account, the SMS method is used. How does one select instead the hardware token? If not, how do I remove my mobile number from my account?

7 Replies

Replies have been turned off for this discussion
  • Jay's avatar
    Jay
    Icon for Dropbox Community Moderator rankDropbox Community Moderator
    3 years ago

    Hi bhagmeister, thanks for bringing this to our attention.

     

    Are you logging back into the Dropbox site, or via the app itself? Have you followed all the steps in this article

     

    We'd recommend keeping the mobile phone number connected in case you lose the Yubikey, as a backup method to login to the account, as without it you won't be able to login again, even from our end.

     

    Keep me updated with any details.

  • bhagmeister's avatar
    bhagmeister
    Explorer | Level 3
    3 years ago

    thanks for the reply. I’ve logged out of the (web) app as well as mobile app. The options presented for primary method is either SMS or Mobile Authentication app - there is no option to promote hardware token(s) as primary method. 

     

     

  • Nancy's avatar
    Nancy
    Icon for Dropbox Community Moderator rankDropbox Community Moderator
    3 years ago

    Hey bhagmeister!

     

    Does the key you wish to use as a 2FA method follow these standards; ‘FIDO Universal 2nd Factor (U2F)' or 'Web Authentication (WebAuthn)', also known as 'FIDO2’?

     

    Can you send me a screenshot of what you see when visiting your Security page, under the Two-step verification section?

  • bhagmeister's avatar
    bhagmeister
    Explorer | Level 3
    3 years ago

    Hmmm. I’ve tried again on both iPhone and iPad to log back into the web app (dropbox.com) and…. both properly asked for my hardware key. Go figure. That said, here are the screenshots in question (see below). You’ll see the choice of only SMS or Mobile App.

  • Hannah's avatar
    Hannah
    Icon for Dropbox Community Moderator rankDropbox Community Moderator
    3 years ago

    Thanks for the screenshots, bhagmeister.

     

    Does this mean that your issue is now resolved, despite what the screenshots show?

     

    Are you required to present your YubiKeys when trying to login, say, from a private browsing window?

  • weka's avatar
    weka
    New member | Level 2
    2 years ago

    Hi, I have to agree with the previous speaker. The hardware key is not offered in the security settings under "preferred method". It would be nice if you could change this. DropBox will only be really secure when I can deactivate all insecure methods. An attacker tests until he finds something to get in. And somehow we all don't want that. For this reason: "preferred" e.g. YubiKey and "backup" sms.

About Security and Permissions

Start a discussion in the Dropbox Community forum to get help with your account security and permissions. Find support from Community members.

Need More Support

The Dropbox Community team is active from Monday to Friday. We try to respond to you as soon as we can, usually within 2 hours.

If you need more help you can view your support options (expected response time for an email or ticket is 24 hours), or contact us on X or Facebook.

For more info on available support options for your Dropbox plan, see this article.

If you found the answer to your question in this Community thread, please 'like' the post to say thanks and to let us know it was useful!