3 ms·
By design TFA uses something one possesses that nobody else does, isn't this identical in principal as the private key? I understand why and how this adds the
by oarmstrong 13y ago
By design TFA uses something one possesses that nobody else does, isn't this identical in principal as the private key?
I understand why and how this adds the extra security for the 'traditional' password authentication due to all the methods of compromising a password: brute force, guessing, exploits etc.; so for TFA to add an extra layer surely the private key would have to be exploitable in some form?
Maybe I phrased myself incorrectly in that I still see how it adds an extra layer of security but I fail to see why one would do this on top of a key based auth method.
I know the original article didn't mention using it on top of key auth but I wanted some insight as to whether or not it would be worth doing. As do many, I use TFA for any online service I can so I do appreciate its point in that sense.
EDIT: I never really considered the fact that the private key could be stolen via malicious software. Taking that into account I see the value in TFA for SSH.