Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No.


> No.

Please explain which parts of my comment are false?

Thank you.


This feature is not 2FA, and your argument is incoherent even if you fix the terminology, because many anti-ATO systems are heuristic and intriniscally "bypassable" by design, and yet you still want services to have them. ATO is an arms race.


This anti-ATO mechanism is asking for a code delivered via email (something you have) in order to grant access to the account. That is authentication via an additional factor, i.e. 2FA.


If you implemented this feature and called it your "2FA system", security engineers would laugh at you. It's clearly not 2FA. And, of course, Paypal has actual 2FA.


> This feature is not 2FA

> anti-ATO

ATO [1] is authentication by definition, but again, depending on how it's implemented, not usually the best form.

[1] https://csrc.nist.gov/glossary/term/authorization-to-operate


Authorization is not authentication, by definition. Furthermore, your link is talking about an entirely unrelated meaning of ATO. I believe tptacek meant it to stand for "account take-over".


You're right; that's what ATO means here.


Same difference. Anti account take over and account authentication, because similar methods would be deployed (i.e., multifactor authentication, heuristic, etc.)


At risk of pointing out the obvious, ATO (as in Authorization To Operate) has nothing to do with logging in, technical authentication, or technical authorization. An ATO is a piece of paper or equivalent that lets your business deploy a product or solution, primarily used in the government space. It’s a contract that a human/organization signs, not a part of the login process for a computer.


No, obviously not.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: