2 ms·
Wouldn't a Google Auth type TOTP be ideal for over the phone? Is there anyone doing this? It could be the same one I use for 2FA to the website. Or, an entirel
by packet_nerd 7y ago
Wouldn't a Google Auth type TOTP be ideal for over the phone? Is there anyone doing this?
It could be the same one I use for 2FA to the website. Or, an entirely offline flow would work too where they sent a dead-tree mail with the shared secret in QR code format.
- organsnyder 7y agoI think that's one of the best solutions, but it would add a ton of customer service overhead for lost devices (if physical OTP generators are used), clock sync issues, device-specific quirks... And if we want to have a universal system for this rather than each service provider having their own one-off solution, someone would need to foot the bill.
- jeltz 7y agoSwedish banks already do this. They first implemnted their own systems with custom hardware (and before that banks mailed a physical scratch pad with codes) but then later together developed a mobile app (called Mobile BankID) which can be used for authentication. So clearly it can be done. Swedish banks have been doing it for at least 20 years.
- deleted 7y ago[deleted]
- jeltz 7y agoYeah, I use something similar with my bank except theirs uses custom hardware and is challenge and response based.