5 ms·
No Google Authenticator support though. No list of backup passwords either. So if I lose SMS access on my phone, but still have my phone, I still can't get into
by jschuur 13y ago
No Google Authenticator support though. No list of backup passwords either. So if I lose SMS access on my phone, but still have my phone, I still can't get into an account from a new device.
- codemac 13y agoI'm very disappointed they don't have Google Authenticator (or maybe some custom HOTP/TOTP app) support. And I imagine Twitter thought of the lost phone/sim card problem, is there really no set of preshared backup keys?
- jschuur 13y agoI'm guessing they just wanted to get this out the door quickly. You get app specific passwords, but they're only good for an hour. By then, your app should have a token that is good indefinitely (and you can revoke from their apps list).
- jlgreco 13y agoHow much more time would it have really taken them to get TOTP out the door? I mean, a toy implementation only takes a few minutes... I get that the scale is completely different and they would need to audit all of their systems, but how long have they been working on this already? I can't imagine they only got the idea that maybe 2FA is a good idea last month. They probably have spent months on this already; had they wanted it from the beginning, would TOTP have really delayed anything?
- StavrosK 13y agoExactly. I really can't see a full-blown SMS system taking less time to integrate than TOTP.
- m0hit 13y agoSeems like this is just an early run to test usage of 2 factor authentication. In my opinion, twitter has different access patterns than Facebook and Google especially with lots of company/product shared accounts. Based on the "..much of the server-side engineering work required to ship this feature has cleared the way for us to deliver more account security enhancements in the future.." I'd expect support for an OTP client soon.