Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Two factor is not a good solution either. Having to lug around your phone pulling up randomly generated strings from an RNG on both ends... defeats the point. Instead of an RNG seed, have a shared secret.

Google Authenticator has TWICE gotten out of sync with my Authenticator apps, including Google's own accounts and my WordPress installs. I've had to turn it off and just resort to single-factor auth, or using stuff like Mailchimp's own app.

2FA is great in theory but it's failed twice for me and it's been a huge hassle.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: