4 ms·
> If the user needs to be loggedin somewhere, they must be online I will be using JWTs, with asymmetric signatures. An internet connection will only be needed
by PranavBerry 5y ago
> If the user needs to be loggedin somewhere, they must be online
I will be using JWTs, with asymmetric signatures. An internet connection will only be needed while adding the device for 2FA. The JWT will be generated from the private key already on the phone so internet is not necessary.
- chinathrow 5y agoWhat problem are you solving? I don't get it.
- PranavBerry 5y agoIf the phone not having a internet/network coverage was a problem, my idea could be useful. It also makes the phone a kind of hardware token, a user can login only if he has his phone. However from the responses it looks like this is not an issue and I'll probably not work further on this idea.
- chinathrow 5y agoYeah I really think it's a non-issue: 2FA apps such as Authy or Google Authenticator already work if the phone is offline.