Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What was the "personal key" that's been deprecated? Was it TOTP, a secondary password, or what?


It was essentially another password. It was a fixed length secret key, Something You Know (well, realistically Something You Write Down hopefully not on a Post It note stuck to your screen although that's better than nothing)

The Blog poster has forgotten or confused themselves into believing login.gov wants them to replace their Google Authenticator style sign-in, but it does not, it wants TWO methods of logging in, and Google Authenticator is only one.

Why does it want TWO?

Because two is one and one is none. Any particular method is always a single failure from being unavailable. You lose the phone, you forget the code, or whatever.

If you have two or more FIDO tokens, it will accept both methods being FIDO tokens, this is the safest option (the government ID might perhaps be as safe or safer but obviously isn't available to lay people so I have no idea)

Google Authenticator and the 10 random codes are next safest and zero cost. You will need to keep them safe, and hope login.gov keeps them safe too, and they're vulnerable to being phished, but otherwise they are pretty good.

SMS is a poor final option. But it is very convenient while also being essentially free so you can see why it had to at least be an option for now.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: