TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Show HN: The easiest 2-factor auth

27 点作者 markkum超过 11 年前

8 条评论

AndrewDucker超过 11 年前
How is it easier than TOTP, which is an IETF standard, and implemented by Google Authenticator (amongst others)?
评论 #7076414 未加载
mmastrac超过 11 年前
Hate to be one of these guys, but the site is totally unreadable on Android Chrome. The left bar covers everything and won't move. Maybe offer a close or collapse button for it?
评论 #7077262 未加载
评论 #7076629 未加载
M4v3R超过 11 年前
We use MePIN in our service and I have to say that it's working really great. Easier for the user and also more secure than Google Authenticator (for which secret key can be stolen more easily).
huhtenberg超过 11 年前
So what happens to my users if your service ever goes down or disappears?
评论 #7076575 未加载
评论 #7076604 未加载
davis_m超过 11 年前
From your home website, it looks like you are relying on users deciding if they should authorize a request based on OS, web browser, ip address, and location.<p>Users are going to essentially ignore ip address. OS, web browser, and location are easy to spoof. If a half competent attacker makes a request, how is the user to know if they should authorize a request.<p>I understand that using OTP codes can be annoying to some users, but it is MUCH harder for a user to hand that code over to someone in order to login.
评论 #7077059 未加载
beefhash超过 11 年前
While two-factor authentication is a good thing from a security standpoint from service providers, I can&#x27;t help but worry that it&#x27;s a worry from an individual&#x27;s standpoint: It&#x27;s nothing but serving an IP address+account &lt;-&gt; mobile phone number relationship on a silver tablet. Do we really want that?
评论 #7078100 未加载
rplnt超过 11 年前
What&#x27;s with those url changes? After a while about a dozen url anchors is cycled through which effectively kills the &quot;back&quot; functionality. If you go past them, you can&#x27;t stay on the &quot;main&quot; page because another ones are added.
评论 #7077155 未加载
davis_m超过 11 年前
What methods are you using to make sure that an authorization comes from an authorized phone?
评论 #7076764 未加载