Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've come across dozens.

Google does it. Paypal does it. Duo does it. Lots of single-sign-on systems do it. All of those including not-TV scenarios, just normal computer-and-phone stuff, as well as sometimes other weird flows. Many of these are far beyond what most would label as "security competent", into "login security is a large part of their business and they have significant numbers of specialists hired".

(it is probably safe to say none are "truly secure" or "actually security obsessed", but I doubt that's actually possible in large quantities. the requirements are too steep, for both implementers and users.)

It's not the most common, certainly, nor anywhere close. But it's very far from nonexistent.



Where does Google do this?


Log in on browser -> push notification "is this you?" on your phone -> browser automatically continues when you say "yes".


But that's only as a second factor right?


Is that materially different? It's a login that's completed on a different machine, and automatically resumes on the intended one.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: