Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I was not suggesting SMS 2FA when I referred to "Smartphone-based solution". I meant relying on Secure Enclave or alike on the smartphone as the second factor in a challenge-response fashion that makes the "OTP" bound to a specific domain and thus unphishable.


Sorry I didn't see the SMS part was a quote of the parent.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: