Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Now if only they gave me a real 2FA option that doesn't actually decrease security. So they made a fancy app where I need to confirm PC logins with a 5 digit pin. But the same app is also their official banking app and lets me do everything with my account, all with the same 5 digit pin. I don't even need to enter the credentials necessary on the PC. This is what you get when the government tries to mandate security.


> This is what you get when the government tries to mandate security.

The NIST actually has great guidelines for digital identity authentication:

* https://pages.nist.gov/800-63-3/sp800-63-3.html

Don't blame the government -- they outlined an ideal way to do it on many levels of need. Blame the specific people who implemented that specific system.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: