8 ms·
Regardless of what is actually uploaded, a phone app and website implementing this would need to get microphone permissions from the user, and it would be diffi
by Niten 11y ago
Regardless of what is actually uploaded, a phone app and website implementing this would need to get microphone permissions from the user, and it would be difficult for the user to verify that raw audio isn't being captured as well. (There's no separate "audio fingerprint" permission.) That could become a barrier to adoption in practice.
I'm also not sure how I feel about a second factor that would allow an adversary to authenticate by simply sitting in the same coffee shop as me. Manual authentication seems important, and U2F already addresses some of the nusiances of TOTP-based schemes.
This is a really clever innovation, though.