2 ms·
> Does anyone honestly believe that these [two-factor auth] things provide additional security? It's like the TSA frisky-crotch-grope of authentication. Yes. E
by johnl1479 13y ago
> Does anyone honestly believe that these [two-factor auth] things provide additional security? It's like the TSA frisky-crotch-grope of authentication.
Yes. Especially as time-based passwords, a-la an RSA token or Google's two-factor auth, since they require something you know (your password) and something you have (the token). They expire and regenerate every minute or so, can't really be remembered or predicted, require access to a physical device that displays the password, and near impossible to predict without information about the seed.