|
|
|
|
|
by munchbunny
2673 days ago
|
|
I believe iPhones now come with on-board TPM's? So in theory you could actually generate the private key on the TPM, and then your phone becomes the "thing you have" to a higher degree of security than authenticator apps. Not sure about any apps that take advantage of that yet, but the hardware seems to be there. |
|
If you use krypt.co, you can store ssh and GPG keys on your phone's TPM, as well as a secret key for use with a browser addon to facilitate WebAuthn. So, you can already use your phone as the "thing you have".