Skip to content

Comment on Want to be more secure? Build two-factor authentication into your webapp

Comments

We hope to launch a service precisely to help with this (toofactor.com). It's great to see this additional attention and options in the space.

Google Authenticator is a great service imho, but I find myself moreso pleased with the 'application specific' password feature which allows me to abstract my exposure even further.

Unfortunately those application-specific passwords aren't particularly application specific, at least in Google's implementation -- any of them can be used for anything.

If someone built a system which could restrict passwords or keys by some kind of capabilities (e.g. my Adium gtalk password could only be used to authenticate to Google's Jabber servers), that would be useful. It would be complex to manage, especially as your applications change over time, but not impossible.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.