Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ideally yes, but let's not let the perfect become the enemy of good. If that's what available right now, it should still be used and recommended.


In practice in many services 2FA is about hoarding PI to target ads, not improve security. I don't buy into that.


TOTP doesn’t expose PII.


Don't you need to send the generator hardware dongle thingy (whatever it is called in English) to the user?


TOTP uses a publicly known algorithm that you can implement yourself. Most people use an app, but that’s not mandatory. No special hardware is required.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: