Re: mobile phone + password = 2 factor auth?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Di Mai 26 2009, Seth Vidal wrote:
> On Tue, 26 May 2009, Till Maas wrote:

> > A problem with phones is, that they are typically not as secure as
> > hardware tokens. Users can install custom software on them. Also the
> > phone may be compromised via bluetooth. It might be even possible to
> > directly access text messages via bluetooth or maybe also wifi nowadays.
>
> But that's the point of it being one factor of two factor auth...
>
> Even if you compromise the txt msg you still don't have the component
> that the user knows. You only have the component that the user HAS.

But one of the two factors in this case should be to own the phone or the SIM 
card to be able to login sucessfully. Which imho should mean that if someone 
is in posession of the phone, he can be sure that nobody else can access the 
two factor protected website. But in this case, you can still own the 
compromosised phone, but someone else might access it and use it.

Regards
Till

Attachment: signature.asc
Description: This is a digitally signed message part.

_______________________________________________
Fedora-infrastructure-list mailing list
Fedora-infrastructure-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-infrastructure-list

[Index of Archives]     [Fedora Development]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite News]     [KDE Users]

  Powered by Linux