4 ms·
authenticator apps +1
by Rebles 3y ago
authenticator apps +1
- vkou 3y agoWhat about people who don't have a smartphone?
- amatecha 3y agoYou could get those little mini RSA token things that are just a battery-powered thing the size of a USB stick. I assume those are still around... haven't used one in years tho.
- jrockway 3y agoThese are pretty insecure because OTPs are easily phishable. WebAuthn devices are just as inexpensive, but prevent most phishing attacks.
- xjay 3y agoThey'll get a government-issued ankle monitor/smartphone..
- foota 3y agoCouldn't you just set up a text service to request a one time token? That way you could fall back to SMS, but it wouldn't be required. (e.g., anyone could create a service that someone could use, which would allow them to request a 2fa code to be issued over SMS at any time after enrolling it via the OTP pairing process)
- vkou 3y agoWhat happens when the attacker uses that fallback to perform the exact same attack that they perform today?
- crotchfire 3y agoThere is no smartphone requirement in RFC 6238. Smartphones are simply the device that a lot of people use as their user-agent, but you can use a computer if you prefer. https://www.rfc-editor.org/rfc/rfc6238 https://www.rfc-editor.org/rfc/rfc6238
- autoexec 3y agoI don't care much for third parties inserting themselves into (and likely collecting data on) things that have nothing to do with them. What kind of authenticator app would make it impossible for the maker of that app to know who I am or what services I'm using and when/how often I use them?