Hacker News new | ask | show | jobs
by mike-cardwell 3917 days ago
Sod the Yubikey. Get a Pebble Time watch and install the QuickAuth app. One press of a button on my watch and I get a list of two factor auth codes for my various services, now including Github. Doesn't require plugging anything into my laptop. Doesn't require my phone to be near me or on. Doesn't require Internet access.
1 comments

TOTP is vulnerable to phishing and MITM attacks. U2F (assuming that you are not MITMed when registering the device) is not.