Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Although I disagree that it's two step authentication in the general use of the term, I actually built this type of authentication flow into Remarkbox (https://www.remarkbox.com)

It works really well for most users although it does have some quirks.



How is it not, even in the general use of the term? Instead of site username and site password plus a separate token to a previously agreed upon authenticated service (whether phone or email account), it's site username and site account email (hopefully hidden), and a token sent to a previously agreed upon authenticated service.

If your account name and associated email is known, it's not really better than a username and password (except that it's delegated to what should be one of your strongest accounts that you protect more diligently), but if the email is not generally known for that account name then it's extra identifying information that must also be known to access the service account.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: