Hacker News new | ask | show | jobs
by nowen 3669 days ago
Google authenticator is only one-factor, possession of the shared secret in the phone. That's why it requires 'two-steps'.
1 comments

Well, the password on the phone is the other factor. No need to send the password anywhere.