7 ms·
>> 1) How is this safer than a standard password manager with TOTP-based 2FA? The second token, either produced by TOTP or something like a Yubikey, would guard
by marcusfrex 10y ago
>> 1) How is this safer than a standard password manager with TOTP-based 2FA? The second token, either produced by TOTP or something like a Yubikey, would guard against keyloggers, since the one-time code is useless after it has been entered.
No matter how many factors you are using, sooner-or-later you pass it with keyboards.And that step may be intercepted and you may think that you sent the second token to the other-side but failed.
I can provide you a special investigation of Sceptive to show how 2-factor-authentications has been bypassed by malwares targeting Eastern-Europe banks.
>> 2) How is the certificate generated, and what is it based on? Is the cert unique per device, or would I copy it to my other devices that need to access Forgiva ala a public key?
It is not unique per device. You can copy it to all devices you use no matter what.
>> 3) There are some typos and other grammatical weirdness on the page that suggests English is not the writer's first language. That's fine, but it looks unprofessional. I can make some proofreading suggestions if you feel inclined. I don't really believe in this product, but I'd prefer it to be judged on its technical integrity rather than the quality of its marketing, so I'd be happy to help polish it up.
It would be an excellent help, we are very unprofessional on language and marketing -as you well see-. Can you please send an e-mail to us at info@forgiva.com to tell us our mistakes?