Soldato
- Joined
- 28 Dec 2017
- Posts
- 9,205
- Location
- Beds
1% chance from a random guess is TERRIBLE security2 digit code challenge.
1% chance from a random guess is TERRIBLE security2 digit code challenge.
I explained it poorly - it's like the opposite of OCUK 2FA. You click login, and then the website gives you the code. You then enter that code into the 2FA app.1% chance from a random guess is TERRIBLE security
Well it puts the onus on definitely having access to the device so there's that. Can't read an SMS notification off of a lock screen or smartwatch etc.I explained it poorly - it's like the opposite of OCUK 2FA. You click login, and then the website gives you the code. You then enter that code into the 2FA app.
So unlike most 2fa where the app gives you the code to provide it to the website, it works in reverse.
I guess it's harder for folk to be engineered to enter a code into an app versus provide a code??
I guess that has meant in turn they've reduced the length of the code from 6 digits to 2.Well it puts the onus on definitely having access to the device so there's that. Can't read an SMS notification off of a lock screen or smartwatch etc.