Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's a bold understatement, you're pretty much fucked without BankID on your phone.


In Denmark, MitID supports non-phone authenticators. You have to request it, but a few days later they send a TOTP generator keyfob. They also have a version for blind people.

I would find it annoying if I had to carry the keyfob. I have it as a backup.

https://www.mitid.dk/en-gb/get-started-with-mitid/mitid-auth...


Why don't they just use RFC 6238 TOTP?


The system is used for authentication for banking, accessing healthcare records, tax records, filing for divorce (yes, online) and so on. And for doing similar things for ones children, depending on their age.

By using an app or various hardware keys — with a maximum of three active methods — they can reduce the chance that additional people have access, and prevent duplication of the private keys. This isn't possible with a QR code to scan for TOTP (you can scan it on multiple devices, or print it out, or have a computer with malware doing this).

Initial authentication is done using a passport, or in-person at a local government office for people without one (or without access to a phone capable of reading the passport's chip).

(This is just my general understanding of the system.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: