Hacker News new | ask | show | jobs
by Hamuko 1463 days ago
>Say you registered via smartphone and now want to login on the desktop - do you tell the desktop user to grab his mobile safari, login and pull up some PIN-No which then to type into the desktop client?

That's basically how it has to be done, at least for on-device authenticators. Granted, you can replace the PIN code mechanism with some other one, like having the website email you a one-time authentication URL that you can then use to access the website to add your desktop authentication.

If you use a portable authenticator (Yubikey), then you can just use the authenticator on the phone and on the desktop. The ones with NFC will perform the same authentication on mobile and desktop.