3 ms·
The problem with security keys is that they're expensive and you have to carry them around. TOTP is cheap and much better 2FA than OTP over SMS.
by IceWreck 3y ago
The problem with security keys is that they're expensive and you have to carry them around.
TOTP is cheap and much better 2FA than OTP over SMS.
- xvector 3y agoSecurity keys can be built into the phone and still provide a reasonable expectation of security, e.g. Apple's Passkeys. Obviously, a YubiKey would be better, but Passkeys don't require you to carry an additional thing and are still more secure than TOTP apps.
- toastal 3y ago> can be built into the phone I don’t like this idea. As a person whose had a phone break, like many others, tying auth to something so fragile should not be preferable. I’ll never forget my phone breaking and the process of trying to order a new one: the online shopping here, Shopee, demanded SMS 2FA (only option) which I needed to purchase a new phone so I found a different vendor but then my bank required SMS 2FA (only option) to do a transfer. At least with these hardware security tokens, they’re pretty ‘dumb’ and often covered in epoxy or other weather-resistant material that makes them quite rugged & durable. Mine have gone through the wash and dangle from my motorbike’s keychain during the monsoons without issue. > YubiKey Please just use a generic term like “hardware security key/token” rather than endorsing a singular brand–especially one that is closed-source and looking to “go public” (https://news.ycombinator.com/item?id=35625065 https://news.ycombinator.com/item?id=35625065). If you think the closed nature of Google Authenticator is bad, consider an open hardware token option rather than a closed one.
- toastal 3y agowho’s* had a phone break
- jkingsman 3y agoThis is sort of willfully missing the point, I concede, but I have my U2F token physically embedded in my arm and have minimal fear of losing it/being without it. Right now it runs OpenPGP and a Yubikey U2F emulator, but it can run just about any flavor of MFA with the appropriate companion app (full subdermal Java Card platform). https://dangerousthings.com/product/flexsecure/ https://dangerousthings.com/product/flexsecure/ Hard agree, though, TOTP >>>>>> OTP via SMS
- gleenn 3y agoThat's some wild Bourne Identity stuff. The thing permanently bricks itself after a specific number of failed attempts. About 3cm long and does TOTP and PGP. Wild.