Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, because you're not authenticating to the service.

Think about what would happen if your phone gets owned by some malware that escalates to root. It can simply log the PIN, extract the key and then login as it wishes. That's because the phone is the single factor for the service.

Compare that with the auth against, say, Gmail, where even if a malware were to own the Authenticator, it still couldn't login as you, since your password goes directly to the service.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: