3 ms·
Exactly. Good two-factor authentication is not hard. World of Warcraft, for example, has had an excellent real-world implementation for years now. It's actua
by vec 13y ago
Exactly. Good two-factor authentication is not hard. World of Warcraft, for example, has had an excellent real-world implementation for years now. It's actually sufficiently not hard that I'm not sure there's really room for much innovation in that space (unless you count banks actually using it to be innovation).
What I'm saying is we need a better solution for Facebook and HN. There's some large subset of sites for which users will not tolerate a physical artifact or convoluted multi-step process. Within those constraints, and with the understanding that we'll never be able to do as well as 256-bit private keys or two-factor, I'm wondering if we can't still do significantly better than alphanumeric passwords.