Live data from Hacker News

The bleak picture of two-factor authentication adoption in the wild

elie.net

31–40 of 96 posts

Re: The bleak picture of two-factor authentication adoption in the wild

#31
post #5

Earlier quoted context omitted.

The thing that is nutty is.. they PAY MONEY for the SMS method! I do not understand why more sites don't support TOTP like Google Authenticator.

Google authentication is great, until it's time to get a new phone.

If you have 1Password it supports OTP and thus can be used across devices.

Re: The bleak picture of two-factor authentication adoption in the wild

#32
Personally I dislike nearly all kind of 2FA for a very simple reason: they add a dependency tie with something big, powerful and outside my control.

For instance I perfectly agree to have an extra, branded, physical token, to log in to my bank, I totally refuse to use a mobile app on my phone to do the same.

Re: The bleak picture of two-factor authentication adoption in the wild

#33
post #32

Personally I dislike nearly all kind of 2FA for a very simple reason: they add a dependency tie with something big, powerful and outside my control. For instance I perfectly agree to have an extra, branded, physical token, to log in to my bank, I totally refuse to use a mobile app on my phone to do the same.

What is the difference between an extra branded physical token and a 2FA app, such as Authy, on your phone?

Re: The bleak picture of two-factor authentication adoption in the wild

#34
post #17

2FA is a user interface disaster, exporting the failures of software security as a huge annoyance on to users. I would rather be hacked than deal with 2FA.

The right way to do it is to use client-side TLS certificates in combination with the username and password. Add in a passphrase for the private key and you could have 3FA. All that's really needed is for browser vendors to improve their UI for generating certificate signing requests and importing certificates.

Meanwhile usability cries in a corner.

Re: The bleak picture of two-factor authentication adoption in the wild

#35
post #32

Personally I dislike nearly all kind of 2FA for a very simple reason: they add a dependency tie with something big, powerful and outside my control. For instance I perfectly agree to have an extra, branded, physical token, to log in to my bank, I totally refuse to use a mobile app on my phone to do the same.

Strange argument. What is this 'big powerful Outside of your control'?

Re: The bleak picture of two-factor authentication adoption in the wild

#36
post #32

Personally I dislike nearly all kind of 2FA for a very simple reason: they add a dependency tie with something big, powerful and outside my control. For instance I perfectly agree to have an extra, branded, physical token, to log in to my bank, I totally refuse to use a mobile app on my phone to do the same.

What is the difference between an extra branded physical token and a 2FA app, such as Authy, on your phone?

One requires a mobile phone to function (and continue functioning), whereas the physical token only needs itself.

Re: The bleak picture of two-factor authentication adoption in the wild

#38
post #35
post #32

Personally I dislike nearly all kind of 2FA for a very simple reason: they add a dependency tie with something big, powerful and outside my control. For instance I perfectly agree to have an extra, branded, physical token, to log in to my bank, I totally refuse to use a mobile app on my phone to do the same.

Strange argument. What is this 'big powerful Outside of your control'?

Google, RSA, ...

Re: The bleak picture of two-factor authentication adoption in the wild

#39
post #32

Personally I dislike nearly all kind of 2FA for a very simple reason: they add a dependency tie with something big, powerful and outside my control. For instance I perfectly agree to have an extra, branded, physical token, to log in to my bank, I totally refuse to use a mobile app on my phone to do the same.

What is the difference between an extra branded physical token and a 2FA app, such as Authy, on your phone?

branded physical token is "a thing from my bank", so something they are responsible for, that for my POV came from them, created and maintained by them, it's not connected to anything and it's a standalone object.

My phone is a connected device, monitoring me constantly outside my control, controlled by the most powerful data mining companies in the planet. I simply can't trust my phone. I can trust enough my physical offline devices and if it will be cracked sometime I'm completely not responsible for it, my bank is. While with my phone it's really easy to say "it's because of this or that, not our faults" where this or that can be anything from unupdated fw (by the vendor, of course), unsafe apps installed, ...

Re: The bleak picture of two-factor authentication adoption in the wild

#40
post #36

Earlier quoted context omitted.

What is the difference between an extra branded physical token and a 2FA app, such as Authy, on your phone?

One requires a mobile phone to function (and continue functioning), whereas the physical token only needs itself.

+1
Post reply on HN