Hacker News new | ask | show | jobs
by geoffsanders 4370 days ago
Just use LaunchKey - https://launchkey.com or https://github.com/launchkey
2 comments

Why on earth would you outsource two factor auth to a cloud service?

Talk about putting all your eggs in the same shared basket.

Funnily; the reason to outsource is exactly about not putting all your eggs in the same shared basket. You outsource the 2nd factor and keep the first factor (passwords) in-house. Implementing everything in-house is a "same shared basket".
So you're dependent on a cloud startup for basic auth and you've got no more security than any other isolated two factor auth system.
looks great, very professional... but it appears not to be free.
If an application wants to offer their users multi-factor authentication with LaunchKey it's free. If the application wants to use it internally for their employees with some of the Pro features or requires forced factors then it starts costing money. Non-profits it's free.