26 ms·
You could go one step further and just put a pin in with the cert or no pin at all and just have seamless logins everywhere. Assuming you are using a physical c
by throwaway581294 5y ago
You could go one step further and just put a pin in with the cert or no pin at all and just have seamless logins everywhere. Assuming you are using a physical cert token.
- u801e 5y agoThen you lose one factor which is the username/password. If someone managed to get your hardware token and was able to brute force the PIN (if there was a PIN set), then they could log into any of your accounts. By requiring both, an adversary would not be able to log in unless they had the certificate and the username/password. Using one of the two would not be sufficient.
- deleted 5y ago[deleted]
- freitasm 5y agoThat's how passwordless works with Yubikeys on Office 365 and Microsoft Accounts.