3 ms·
Not so useless. A user of that could memorise the times/dates where a particular easy-recall code comes up. With that, they have effectively "transferred" 2FA f
by robxorb 2y ago
Not so useless. A user of that could memorise the times/dates where a particular easy-recall code comes up. With that, they have effectively "transferred" 2FA for those times into their brain, and not need to use any 2FA app (at only those times).
- hnbad 2y agoGood luck memorising a number of 30 second windows and hitting them exactly. That would require a level of organisation, timing and self-discipline I can not fathom.
- robxorb 2y agoWell, the thirty second window in practice is usually a 2 - 3 minute window, as TOTP servers are set up to allow for drift, network issues, human slowness etc. For sure, memorising more than a handful may be hard but it's just "11 Nov 14:35", etc. I wonder if something could be set up to be both more secure, and more tailored to this use-case. Be pretty sweet to embed a 2FA in users brains somehow.
- 8organicbits 2y agoI think it would be easier to use HOTP for that as the codes are one time use and aren't time based. The user just needs to memorize one of the next N codes.
- masfuerte 2y agoIf you are able to choose the seed you could brute force it so that it produced a memorable code at a memorable time.
- robxorb 2y agoThat's a very cool idea, with the caveat that if an attacker knew you were doing that, the search space for your key would shrink.
- dotancohen 2y ago> Be pretty sweet to embed a 2FA in users brains somehow. 2FA already has a concept of "Something that you know". Still, "Something that you could calculate without revealing the thing that you know" is an interesting concept.
- refulgentis 2y agoThis is a fascinating idea. Would you mind if we call it a "cryptographic hash"?
- dotancohen 2y agoWell, it's been a long time since then, but I've had some crypto and some hash mess with my brain. ))