Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> more secure because it is tied to a device

Tied to a phone (as opposed to some security-specific device like a Yubikey) is a terrible idea.

It ties your authentication to something that is often lost or damages, but more importantly, something that is controlled by a third party (apple or google) and requires an expensive monthly subscription to yet another third party (your cellphone company).

TOTP is not tied to a device which is why it's a beautiful solution. You can store it where you wish under the controls you wish and back it up as you wish. You are fully in control, dependent on nobody.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: