Live data from Hacker News

Show HN: Faktor – The missing 2FA code autocomplete for Chrome

getfaktor.com

51–56 of 56 posts

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#51
post #50

Earlier quoted context omitted.

I just went round and round with my bank about needing my phone number so they can text me a TOTP. You know, for security. They just can't quite seem to wrap their head around how having the same device running their banking app that also receives the text is not secure when the device is no longer in your possession.

If they're texting you it, it's almost certainly not TOTP.

Their words, not mine. I probably should have put it in quotes

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#52
post #50

Earlier quoted context omitted.

If they're texting you it, it's almost certainly not TOTP.

Their words, not mine. I probably should have put it in quotes

Huh, TOTP and HOTP are pretty technical terms, and I generally don't hear them in places meant for general consumers to read (e.g. even Google Authenticator, which does TOTP and HOTP, doesn't say TOTP or HOTP). The general term, OTP is much more common, and is accurate for SMS.

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#53
post #52

Earlier quoted context omitted.

Their words, not mine. I probably should have put it in quotes

Huh, TOTP and HOTP are pretty technical terms, and I generally don't hear them in places meant for general consumers to read (e.g. even Google Authenticator, which does TOTP and HOTP, doesn't say TOTP or HOTP). The general term, OTP is much more common, and is accurate for SMS.

Soooo, now you're arguing with me about what the person on the phone said? Where does that take the conversation?

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#54

Earlier quoted context omitted.

Sounds like one factor auth with 2 passwords

Its called two step verification. Prevents someone from “guessing” the password but doesn’t stop someone who has physical access to the device with the password stored. Same as with e-mail or SMS codes, basically. I don’t think i recall any websites that detect i am using my phone and rely on a true “second factor” aside from enterprise applications where i got a hardware yubi key.

It is called 2 factor or multi-factor authentication. It should be something you know (password) and something you have (device). Storing totp with your password defeats the entire point of it.

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#55
post #52

Earlier quoted context omitted.

Huh, TOTP and HOTP are pretty technical terms, and I generally don't hear them in places meant for general consumers to read (e.g. even Google Authenticator, which does TOTP and HOTP, doesn't say TOTP or HOTP). The general term, OTP is much more common, and is accurate for SMS.

Soooo, now you're arguing with me about what the person on the phone said? Where does that take the conversation?

I'm not trying to argue. I'm just saying that it's strange.

Re: Show HN: Faktor – The missing 2FA code autocomplete for Chrome

#56

> One-time payment A license for Faktor is one-time purchase that gives you a life-time license. While nice for users, this funding model kills anything bigger than a 1 man project in todays world. Turns out users pay one-time but software developers prefer their salary not to be paid one-time.

Yeah, that doesn't mean your users should pay indefinitely because you cannot live off of that product alone. Work on something else.

The world is full of software that thinks it's worth $5/month,and it's not.

Make a software, reach a finish point, stop developing it and work on something else. Then that software can be a one time purchase and if it really needs an update, charge for it.

Post reply on HN