Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To be fair if your phone is locked with a pin then we're still at least roughly in "something you have and something you know" territory.


Very roughly. When you put in your phone lock pin, you are not authenticating with the website. So roughly, it's not.


I dont see how that matters. You still need a password + one file (on the phone). SSH keys with passphrase are two factors as well in my book. In fact, I would say that not having to transmit the weakest part (the mnemonic password/pin) over the wire is a plus.


I dont see how that matters.

Please tell that to anyone thinking of hiring you for security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: