Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Lots of options.

* You can buy a hardware token. https://www.duosecurity.com/product/methods/hardware-tokens

* You can have Duo call/text you every time you want to log in.

* You can use some other device you have that runs a mobile OS. I had Duo set up on my wifi-only iPad while I was using a feature phone for a few months a year ago. (I eventually gave up on that and got a smartphone, though.)

* You can buy a used/cheap smartphone, iPod Touch, or similar, install either the Google Authenticator or Duo app, and not use mobile service at all. You just need a bit of wifi to enroll.

* You can write an OATH client as a J2ME MIDlet. When I was using a feature phone, I spent some time figuring out how to compile J2ME apps in 2015, by piecing together ten-year-old tutorials. It works fine; if you want me to dig up details let me know. (Alternatively, someone may have written one already, but I didn't search very hard.)

* You can, technically, run an OATH client on your computer. But at that point, you take responsibility for your two-factor auth being slightly less than two-factor.



To you last point... it's funny the number of companies that are using virtual 2fa clients on their laptops for VPN connections because they wanted to save money on hardware tokens. kind of negates the second half of 2fa.


It doesn't. The only case when it's worse is when your laptop is stolen and you don't know about that - very unlikely for corporate laptops


Or, monitoring software on your computer, the origin of which now has access to the computer, your password, and the token generator.


No, if your computer is infected (=monitoring software) there's no difference because token is transaction-agnostic. 2fa won't help


If you have a hardware token, not on the computer.. and use that as part of your VPN, if your computer is compromised, your account won't be able to be used to reconnect to VPN while you are afk without that hardware token... if the software/key are on the machine, they have your password, and the generator for 2fa... they don't even need your machine anymore... that is definitely less secure.


I have a Nokia 1020 Windows Phone. There is a Duo app for it, but it's single account. Duo hasn't updated their WP app since 2012.


I also have a Windows Phone. There's an official Microsoft 2FA app that I use instead of Google Authenticator or Duo, including now for multiple Slack accounts. http://www.windowsphone.com/en-us/store/app/authenticator/e7...


Slack was nice enough to point this out too. Works perfectly with the QRCode.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: