Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is awesome. Truly a modern-day way of securing boxes.

Of course, it makes it more of a hassle to maintain a machine, and you might get temporarily locked out if their VOIP line or whatever goes down, but the same could be said about fingerprint readers. I personally try to avoid those mechanisms if at all possible, but it's great that someone is offering this as a simple service. Really cool!



You actually don't get locked out if their service goes down (I happened to have asked them this the other day), it fails the other way by default.

Edit: See jonoberheide's explanation below for more info.


That's a rather bad default. If you need two-factor authentication for a system, you probably want it to remain locked.


I disagree. Having a 2FA that sometimes (i.e. very rarely, but not never) goes down is still safer than no 2FA, and I can never afford to be locked out of my server.

However, I could also see the opposite case being made. And I assume this is precisely why they made it an easy config change, to make it behave however you prefer.


For strictly secondary authentication, it's much more likely that an admin will lock themselves out through local misconfiguration than an attacker will find the mechanism disabled.

It's also a one-line configuration change.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: