Hacker News new | ask | show | jobs
by himom 2950 days ago
Grrr. Google Authenticator and such are free. It would be mostly user support costs to deploy. Heck, could even SMS or robodial (Twilio etc) a TOTP code for people without smartphones.
2 comments

> Heck, could even SMS or robodial (Twilio etc) a TOTP code for people without smartphones.

SMS is not secure for this purpose since there are many attacks which allow you to sniff SMS messages.

There's no need for that, TOTP runs everywhere, including J2ME apps installed from WAP.