Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No 3rd party is involved. You're localizing the 2nd factor of authentication. Google could burn down tomorrow andb cease to exist, you could still use authenticator. It's a cryptographic verification scheme, not a service.

RSA was a big one that was similar. Not sure if it's still used today but there was a little hardware fob that wasn't connected to the internet or anything, the whole thing works on Time. The only thing that fob needed was a constant battery power, if it died you'd have to replace the battery and call the helpdesk to get it resynced with your account. The only thing your phone needs is a good time source like GPS or network time. I believe authenticator app works even if your phone doesn't have service. You could be on a landline in a remote region with no Internet, talking to your significant other on the other side of the world, have them log in to your account and give them the code displayed by the authenticator app and they could send that important email you forgot.



RSA SecurId - big problem with that was RSA had the tokens’ seeds, as well as their customers. Recalling all their customers’ tokens after getting hacked back in 2011 must have been expensive.


Big oooof, wasn't aware of that. I believe TOTP works much differently based on my CLI interaction with it, but an expert would need to confirm.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: