logoalt Hacker News

LelouBillast Wednesday at 6:28 PM2 repliesview on HN

How is it not a second factor ?

It's something else that is unrelated to your password that you have to provide in order to log in, is that not the definition of a factor of authentication ?

Because it's phishable ?


Replies

jerflast Wednesday at 8:02 PM

Passwords are "something you know". TOTP is "something you know". It wanted to be "something you have", but it's not. Proof: I can put TOTP tokens into my password manager now. Anything that can go into my password manager is proved to be "something I know" by the fact I can put it into my password manager.

Incidentally, passkeys go into my password manager too. You can probably work the math from there.

(I'm heterodox on this matter, though. I don't believe in the existence of "things you are" and "things you have". I think it's all ultimately just "things you know" and it's all better analyzed in terms of the cost of knowing and proving knowledge, and that the 3-factor framework for authentication is wrong.)

show 3 replies
Spooky23last Wednesday at 10:19 PM

It’s a second password - not a bad thing, but still vulnerable to many categories as attacks.

show 1 reply