Earlier quoted context omitted.
The thing that is nutty is.. they PAY MONEY for the SMS method! I do not understand why more sites don't support TOTP like Google Authenticator.
Google authentication is great, until it's time to get a new phone.
The bleak picture of two-factor authentication adoption in the wild
91–96 of 96 posts
Re: The bleak picture of two-factor authentication adoption in the wild
#92It completely blows my mind that blizzard got it right over a decade ago with a dedicated physical device that would generate a one-time, time sensitive key for second factor authentication (to protect my video game account). Where as I feel I'm still waiting for my bank (actual money) to catch up. they took the easy way out by sms-ing me a second factor authentication key. Even though phone number theft is a known a…
It would be great if everyone adopted TOTP, I'm up to a dozen sites in Authy and it's fantastic. Still waiting for my actual banks to support it though.
Re: The bleak picture of two-factor authentication adoption in the wild
#93Earlier quoted context omitted.
If you have 1Password it supports OTP and thus can be used across devices.
Whenever discussing this with colleagues there’s always been a bit of debate about whether OTP inside 1password constitutes 2FA or not. On the one hand a password could be popped from the target site or phishing, and you’d still need the 2nd factor from 1password to get in. But on the other hand, if you leave your phone lying around unlocked with a poor master password, both get popped together.
Re: The bleak picture of two-factor authentication adoption in the wild
#94It completely blows my mind that blizzard got it right over a decade ago with a dedicated physical device that would generate a one-time, time sensitive key for second factor authentication (to protect my video game account). Where as I feel I'm still waiting for my bank (actual money) to catch up. they took the easy way out by sms-ing me a second factor authentication key. Even though phone number theft is a known a…
Re: The bleak picture of two-factor authentication adoption in the wild
#95Earlier quoted context omitted.
Strange argument. What is this 'big powerful Outside of your control'?
Google, RSA, ...
Re: The bleak picture of two-factor authentication adoption in the wild
#96Earlier quoted context omitted.
TOTP is old and busted, U2F is the new hotness. https://en.m.wikipedia.org/wiki/Universal_2nd_Factor
> The device key is secured against duplication by a degree of social trust in the commercial manufacturer TOTP sounds much better. Also doesn't requires "trusted magic hardware"