Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

2FA apps will never be perfect and allowing careful access is not going to undermine them.

And the alternative is taking a picture of the QR code.

> Additionally just because someone is using a device that doesn't mean that the current user is the owner of the device.

Yeah that's why you make the owner authenticate. It would be ridiculous to use that as a reason to make escalation impossible.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: