Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I could have two computers, and I could also login to an app on my phone. There are valid reasons for a desktop authenticator app.


Phones tend to have much better security models than normal computers. So having both on a phone is much less of a risk than both on a computer. But if you're offering people to weaken their own security by increasing convenience, you're breaking your own security model anyways. You might as well let people opt out of MFA altogether, but fewer and fewer companies tend to do that. Not because technical edge cases might pop up, but because most people are lazy and that is dangerous.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: