Live data from Hacker News

Ask HN: 2FA hardware?

news.ycombinator.com

11–14 of 14 posts

Re: Ask HN: 2FA hardware?

#11
One option might be something like a Pebble. I use mine for H/TOTP codes just fine => https://github.com/JumpMaster/QuickAuth. It's always with you and works completely offline and outside of any service.

It still requires your phone to add seeds, but they are generated completely independently once seeded. Just an idea that doesn't require buying specializes single-task hardware.

Re: Ask HN: 2FA hardware?

#12
Everybody recommending Yubikey: because this [0], use that [1] instead. Amazon uses Gemalto [2] for AWS MFA, but I've had bad experience with it, and cannot recommend it.

[0]: https://plus.google.com/+KonstantinRyabitsev/posts/4a7RNxtt7...

[1]: https://www.nitrokey.com/

[2]: http://www.gemalto.com/

Re: Ask HN: 2FA hardware?

#13
You could use any kind of hardware token like RSA, Fortinet or many other manufactors. The usually offer a software version four your desktop as well. But usually you'll hate this additional piece of crap in your pocket. The combination of something in your mind (password) and something in your hand (smartphone) is the optimal setup. If you have a password or fingerprint to unlock your phone and the token generator app for 2FA it should be enough security.
Post reply on HN