Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How about 2-factor authentication, as discussed in the article?


SMS is not global and is quite expensive to get started with. Only the major players like Google can roll out worldwide SMS authentication. Email is out of the question because it often takes several minutes to receive an email (due to POP-fetching intervals etc)


Google supports HOTP-based codes that can be generated by a mobile application or even a local bookmarklet. They also support printed one-time codes.

Here's the open source project for the mobile app and PAM module: http://code.google.com/p/google-authenticator/

(Disclaimer: I worked on this.)


The 2-factor auth process doesn't use SMS, it uses a one-time-password generator app that you can run on modern smartphones.


You don't need to have data access to use Google's two-factor authentication.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: