Hacker News new | ask | show | jobs
by MacsHeadroom 4046 days ago
Even if it is two-factor, for the reasons you described, it's all over a single channel. There is no out of band mechanism- meaning this can easily be MITM'd. UNLOQ is poor authentication security in more ways than one.

By the way, the founders of Duo Security hold the patent on completing an authentication from a smartphone. Something to keep in mind. http://www.google.com/patents/US20110219230

1 comments

It looks like that patent had a final rejection in 2013. http://portal.uspto.gov/pair/PublicPair (13/039,209)