3 ms·
> and if there are biometric sensors that make > sharing login information impossible (but that > would annoy people more, not help them). Just add 2-f
by my_ghola 9y ago
> and if there are biometric sensors that make
> sharing login information impossible (but that
> would annoy people more, not help them).
Just add 2-factor-authentication tied to their phone. You can use Google Authenticator (RFC 6238).
- mschuster91 9y agoThat one is easy, simply share the secret.
- pja 9y agoThe system is setup not to reveal the secret once it’s set. Technical users can root their phones to extract the secret of course, but most users wont be willing to go that far. You can of course set up a new secret & share it with multiple phones at that point. Not sure there’s much you can do to stop that using a software 2FA implementation. If it really matters, then a hardware token is the way to go.
- ce4 9y agoThe 2FA secret is just a URI, nowadays embedded in a QR code and easily photographed or scanned using any of the 2d barcode scanner apps.
- supergreg 9y agoThen generate a session id and invalidate the URI after first use.
- pja 9y agoIt’s not a URI. The google-authenticator pam library generates an image that encodes the secret which gets echoed to the terminal as a QR-code. No internet access required - just a camera on your phone to image the code. If you can take a photo of the code & re-use it, then you can initialise multiple phones with the same secret.