3 ms·
While the article admits that this isn't very secure, I think giving any visitor a one in three chance to "authenticate" with any given mobile number is well be
by alexbock 11y ago
While the article admits that this isn't very secure, I think giving any visitor a one in three chance to "authenticate" with any given mobile number is well beyond "not very secure" and into "false sense of security/no security at all" territory.
The introduction indicates that this is intended to be on par with confirmation emails or six digit SMS pins, but both of those actually prove that you own the indicated resource; asking someone which of three emojis they received does not.
- theoh 11y agoI'm not up to date on terminology to do with two-factor authentication, but shouldn't it be "currently possess" rather than "own" the resource or device in question? It is important to remember what can go wrong and invalidate the assumptions of the protocol, e.g. theft or duress.