Hacker News new | ask | show | jobs
by ghgdynb1 1921 days ago
I use 1Password for my mfa; I can access my one time passcodes from any device I’m signed in on, and my passwords and secondary authentication are conveniently managed together. If issues like water damage or losing your device are concerns for you, their service might be worth checking out.

Disclaimer: I’m very far from a cybersecurity expert.

1 comments

Two problems I see with this approach...

1. Consumers are terrible at security. Asking them to subscribe to a password management/MFA tool is likely to fail. If this were baked into iOS/Android, this would be better.

2. Many banks don't support this MFA scheme. A quick poke around 2fa.directory shows a massive number that don't support MFA at all, and another huge bunch that do SMS/email but not software/hardware. This puts consumers in the position of juggling multiple MFA schemes to access various sites.

I don't disagree with you in principle. But until there's a more standard approach to MFA, people will continue to use SMS because it's easy and broadly available as an MFA scheme.

On top of that 1Password is quite pricey, albeit fully featured. I probably wouldn't use it if not for my family's plan.