3 ms·
Thinking about the user experience for this. I want to authenticate, so I hunt down my phone, launch an app, scan a code, press a button in the app to submit. T
by asgentile 13y ago
Thinking about the user experience for this. I want to authenticate, so I hunt down my phone, launch an app, scan a code, press a button in the app to submit. This seems to me like quite a long process versus the traditional typing in a username and password. What about the implications of a stolen phone?
- richardjs 13y agoWith the traditional username/password system, you have to remember a unique, secure password for each site--or else you use a password manager, which involves more steps as well. He's also mentioned that this could be adapted into a browser plugin, so that would streamline use on a trusted machine. As for losing the phone, he suggests a passphrase-like "local password" on "The user's view of the application" page [1]. [1] https://www.grc.com/sqrl/userview.htm https://www.grc.com/sqrl/userview.htm