4 ms·
Unfortunately the EU regulation makes the truly user controlled 2FA methods essentially non-compliant. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri
by buzer 1y ago
Unfortunately the EU regulation makes the truly user controlled 2FA methods essentially non-compliant.
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32018R0389 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
> Article 7 Requirements of the elements categorised as possession
> 1. Payment service providers shall adopt measures to mitigate the risk that the elements of strong customer authentication categorised as possession are used by unauthorised parties.
> 2. The use by the payer of those elements shall be subject to measures designed to prevent replication of the elements.
- jojobas 1y agoThis says something along the lines of "it should be hard to extract the TOTP secret". However if you can get so far as to get the secret from the TOTP app, you can as well back up the entire phone and restore elsewhere, can't you?
- nh2 1y agoNo, because phones that lock keys in hardware effectively prevent that, and that works only with hardware that prevents its owners from having full control an doing what they want with their hardware. "Unextractable keys" works with hardware that you don't "truly own".