Earlier quoted context omitted.
I'd think the biggest draw would be not developer ease as much as end-user ease. This way, an end user with an Authy account would only have to give their phone number out once, to Authy, or install one app from Authy, and automatically be able to use two-factor authentication on any site that supports it. It's like OpenID for the second half of two-factor auth.
Give your phone number once to Authy and then to every app that wants to use Authy.
Authy (YC W12) launches two-factor auth as a service
31–40 of 40 posts
Re: Authy (YC W12) launches two-factor auth as a service
#32Earlier quoted context omitted.
Unless my mom's knitting forum also is an online trading platform, why do they need two factor auth? And how likely is it that their software of choice doesn't have a Twilio plugin?
Because your mom probably uses the same password on her knitting forum as she does for her bank website or email or ...
Re: Authy (YC W12) launches two-factor auth as a service
#33Earlier quoted context omitted.
If you're able to build the solution using Twilio (or anything else), then I'm pretty sure Authy isn't for you. I think it's clear that their eventual product is going to be a simple, drop-in that enables two-factor on your mom's knitting forum.
I'd think the biggest draw would be not developer ease as much as end-user ease. This way, an end user with an Authy account would only have to give their phone number out once, to Authy, or install one app from Authy, and automatically be able to use two-factor authentication on any site that supports it. It's like OpenID for the second half of two-factor auth.
Re: Authy (YC W12) launches two-factor auth as a service
#34Re: Authy (YC W12) launches two-factor auth as a service
#35Very neat service. The Duo Security team also has a similar product with a lot of features: http://www.duosecurity.com/ They make the X-Ray Android vulnerability scanner ( http://www.xray.io/ )
Re: Authy (YC W12) launches two-factor auth as a service
#36Earlier quoted context omitted.
Because your mom probably uses the same password on her knitting forum as she does for her bank website or email or ...
The solution to that is not to add two-factor auth to the forum but to fix the problem at its source, with a password manager or something like that.
Re: Authy (YC W12) launches two-factor auth as a service
#37Earlier quoted context omitted.
The solution to that is not to add two-factor auth to the forum but to fix the problem at its source, with a password manager or something like that.
That's not something the forum can control, though, is it? Nor anyone else who's the target audience for Authy, for that matter.
Now, sure the password on that knitting forum might be the same as your bank online account. But the point is that only websites where your account is sensitive needs to add two-factor authentication.
I should have phrased my comment above another way: the solution to password re-use is not to add two-factor auth to a knitting forum, but to add it to the bank website, email provider, etc. anywhere your account's safety matters.
(I was thinking more from the point of view of the user: if they start to get worried about their accounts getting hacked, two-factor auth on the forum is not the solution, a password manager is)
Re: Authy (YC W12) launches two-factor auth as a service
#38I want interaction-free TFA in my phone. I want to be able to walk up to a computer, put in my username and maybe a PIN, and subsequently have every website log me in because the browser knows my phone is on the same LAN as the browser or is in NFC or Bluetooth range. But I would especially want this if the TFA is running on a separate system from the main CPU in my smartphone, only sharing radio/networking hardware…
This is a horrifying prospect. One that you would trust a LAN, two that you would want any external device to QUERY the credentials and access the creds of another device. Horrifying. There are so many better ways of providing zero interaction auth that is secure: BrowserID, NFC (smartphones that can thus do asymmetric encryption), the QR experiment Google did. Even if you just tweaked your idea to do something along…
I'm horrified that people jump to such stupid conclusions. There is no need for one machine to query credentials of the phone or vice versa. The browser just sends out a signal and the phone can supply the 2nd factor to the server.
Re: Authy (YC W12) launches two-factor auth as a service
#39Earlier quoted context omitted.
I hear you. I designed authy so that 1 token would work accross sites for this same reason. Unfortunately its not technically possible for us to allow you to install RSA, Google in our App, as that would mean we would need access to their private seed, which they don't allow.
Are you sure? http://en.wikipedia.org/wiki/Google_Authenticator