2 ms·
Does anyone remember their crazy Ovaltine-decoder-ring two factor auth that they had for a while? They mailed you a physical card with custom grid of numbers an
by qgin 2mo ago
Does anyone remember their crazy Ovaltine-decoder-ring two factor auth that they had for a while? They mailed you a physical card with custom grid of numbers and letters and the login challenge would be to submit the letters an numbers at various grid points.
- zbentley 2mo agoThat type of system is actually still in use in a lot of industries—either as a primary factor or a fallback for folks who might need to log in without a working device. Think healthcare workers who forgot their phone but need to order a surgery, or outdoor safety workers updating the toughbook after a day of work that might damage phones.
- altairprime 2mo agoI still have mine! It was really excellent before camera phones.
- fallinghawks 2mo agoYes, I had one of those cards. It made you feel like you were accessing government secrets. In 2007.
- britta 2mo agoI’ve compiled the entire sordid history of TreasuryDirect authentication in their Wikipedia article: https://en.wikipedia.org/wiki/TreasuryDirect https://en.wikipedia.org/wiki/TreasuryDirect
- qgin 2mo agoThis is amazing, thank you
- SoftTalker 2mo agoSo like a one-time-pad? Except not, since it sounds like they re-use it for each login. If they had sent you a pad of codes, with instructions to tear off the top page each time, that would be closer.
- Gormo 2mo agoA one time pad would have a finite number of uses available, which could lead to logistical complexity if it was being used as a primary auth mechanism. The card actually makes sense, as it amounts to a physical artifact that implements a unique encryption key. If there's enough entropy in generating the card, and the process of using it encodes enough bits of data, it's probably a reasonable solution.