Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I just stopped called it 2fa, and just otp for “one time password”, the URI standard calls it otp:// as well

see problem solved, no need to debate how single or two factor a thing is and you can just focus on the attack vectors it actually still solves for, objectively

yes the password vault is a single point of failure if someone knows your vault password or key logs it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: