Earlier quoted context omitted.
I just went round and round with my bank about needing my phone number so they can text me a TOTP. You know, for security. They just can't quite seem to wrap their head around how having the same device running their banking app that also receives the text is not secure when the device is no longer in your possession.
Sounds like one factor auth with 2 passwords
Show HN: Faktor – The missing 2FA code autocomplete for Chrome
41–50 of 56 posts
Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome
#42Earlier quoted context omitted.
1Password already has support for this. Some would argue that you're defeating the purpose of 2FA if it's stored in the same way as your password, but it is pleasant.
Does 1Password do SMS based 2FA code filling? I use it for sites where they let me use any compliant auth app, but I've not seen a way to get it to work for SMS codes.
Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome
#43Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome
#44Why not bitwarden?
The level of friction Bitwarden adds as compared to 1Pass is staggering.
Also, their Firefox extension eats resources like a new baby (I had to disable it because just a handful of tabs [1] were killing my machine).
[1] May be a little more than a handful, but having to disable an extension so that your machine behaves normally is telling.
Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome
#45Earlier quoted context omitted.
My view is that totp/2FA prevents someone with only your password from logging in. Having the totp seed inside a password manager doesn't break this goal, so I'm fine with it. Of course it means if my password manager gets hacked, there's everything to log in inside, but I'm more concerned about services leaking password hashes that get broken, or accidentally getting phished (and giving up a password + totp combo th…
I just went round and round with my bank about needing my phone number so they can text me a TOTP. You know, for security. They just can't quite seem to wrap their head around how having the same device running their banking app that also receives the text is not secure when the device is no longer in your possession.
Besides being able to unlock the phone in the first place obviously.
Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome
#46If your 2FA code is as autocompletable as your password, is it really a second factor?
Yes — because 2FA is commonly stored on a separate device (phone), people are very quick to conclude that it is pointless otherwise without thinking further. Even if it is stored in your password manager, it is still useful. Consider the case where your network or website is compromised: the password is compromised and can be reused, but the totp 2fa that is in your password manager still prevents login by anyone who…
Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome
#47Earlier quoted context omitted.
I just went round and round with my bank about needing my phone number so they can text me a TOTP. You know, for security. They just can't quite seem to wrap their head around how having the same device running their banking app that also receives the text is not secure when the device is no longer in your possession.
Doesn't the attacker still need to know the password to the banking account, or the master password to the password manager? That'd be the second factor. Besides being able to unlock the phone in the first place obviously.
Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome
#48I'm glad to see someone making this for Chrome. I really like how Safari does it. It can check mail and messages, then delete the message after verifying. One of the reasons why I am finding it difficult to switch from safari.
Broken websites aren't enough of a reason to switch?
Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome
#49Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome
#50Earlier quoted context omitted.
My view is that totp/2FA prevents someone with only your password from logging in. Having the totp seed inside a password manager doesn't break this goal, so I'm fine with it. Of course it means if my password manager gets hacked, there's everything to log in inside, but I'm more concerned about services leaking password hashes that get broken, or accidentally getting phished (and giving up a password + totp combo th…
I just went round and round with my bank about needing my phone number so they can text me a TOTP. You know, for security. They just can't quite seem to wrap their head around how having the same device running their banking app that also receives the text is not secure when the device is no longer in your possession.