3 ms·
Yes exactly, that's the idea with that tool, this would make the process compatible with most services (I'd hope, that all services that require this level of a
by gioazzi 4y ago
Yes exactly, that's the idea with that tool, this would make the process compatible with most services (I'd hope, that all services that require this level of attention also offer TOTP).
I believe the sensible next step would then be to implement a mobile authenticator app for this protocol, that can scan QR codes, perform the initial "split", send out the shares, and then orchestrate the generation with other players.
The initial step is the weak link: the user could just store that TOTP secret and everything else becomes pointless. It'd be great to have the service itself (e.g. AWS) generate those shares on their end and send them out individually.
But then again, a malicious actor with that kind of access to begin with would have a thousand other ways to do some damage.