Hacker News new | ask | show | jobs
by proxynoproxy 619 days ago
I did the same thing at your age, re school, so I understand. I also liked coming up with auth schemes.

One thing I would suggest is dropping the mail component and not involving it at all - you are using this as a weak second factor, exportable; monthly rotation. Bind it to a hardware key instead and use proper cryptography.