2 ms·
It depends on the attack vector you're trying to protect against. If you're on a machine you control (e.g., a personal laptop) and can vouch for its security --
by jonburs 16y ago
It depends on the attack vector you're trying to protect against. If you're on a machine you control (e.g., a personal laptop) and can vouch for its security -- that is, you're sure there's no kind of spyware installed -- https should be sufficient protection when connecting on public networks (especially open wireless connections).
Two-factor auth, on the other hand, protects you when you can't guarantee the security of the machine you're using -- someone able to capture the logon sequence won't be able to replay it at a later point in time.
Note that two-factor auth without https isn't clearly of huge benefit, as an attacker with access to your network may be able to capture the session token (e.g., through firesheep or similar tools).
- Lost_BiomedE 16y agoThank You, that clears it up for me. I don't think I am able to upvote you, or haven't figured it out. Maybe someone else will, for your kindness and time.