Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

TOTP apps are fine, if they're properly implemented (either completely on-device, or properly encrypted before stored in cloud). Services should properly implement account restoration codes if access to TOTP secret is lost. SMS should never be used for 2FA, ever.


There are some apps that if my TOTP secret is lost, as horrifyingly annoying as it would be, I'd much rather need to take the time to get a registered public notary to stamp that they saw me in person, and checked my ID or other such documents, before the account recovery process can begin.

The "old ways" are usefully slow, have protections built around them for centuries of our culture, and I'd rather the annoying administrative headache and "slow" over the quick abuse of account recovery systems for theft and fraud.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: