4 ms·
Remember kids, it's 2FA before the fact, not after. 2FA is not a magic bullet though, and neither is salting. Salting makes it _expensive_, but not impossible f
by getdavidhiggins 12y ago
Remember kids, it's 2FA before the fact, not after. 2FA is not a magic bullet though, and neither is salting. Salting makes it _expensive_, but not impossible for pass recovery. Always aim for impossible. You want to be able to throw away the key during an incident.
- tomjen3 12y agoThe only impossible system I know of would be one that uses client side certificates, but I would be surprised if anybody those in a successful business.
- zrail 12y agoUS Government systems typically use client certificates as a component of access control in the form of the Common Access Card[1]. Not that that's a business, or even a success from the point of view of the users, but it's one of the largest deployments of client side certs out there. [1]: http://en.m.wikipedia.org/wiki/Common_Access_Card http://en.m.wikipedia.org/wiki/Common_Access_Card
- tomjen3 12y agoUnfortunately the only reason they can do that is that they are the government.