Hacker News new | ask | show | jobs
by Damogran6 2885 days ago
Usually in a higher security environment, we'll make sure the authenticator is a separate device (phone or hard token) and expressly forbid having a soft token on the same device that has the password safe.