Hacker News new | past | comments | ask | show | jobs | submit login

For my workplace it was a choice of downloading duo on the phone or getting sms codes. In the past year they cut out the sms codes, now you get a temporary code from the duo app you need to enter into the login portal vs just a push to duo.



There are TOTP apps for regular computer. I am using an old tablet for the microsoft authenticator and banking apps.

Technically it is pretty much like a phone but it is not used as a phone. No number, no sim card.

I am pretty sure some of these apps could work on waydroid too if needed.

So in the end all this discussion really depends if we are talking about the mobile device as a whole that you carry with you nearly all the time or some parts of the ecosystem that you may have at home.


There are hardware tokens. But, yes, not everyone supports them.


Maybe there is a market for minuscule TOTP devices. Just 7 segment displays for the code and the lowest res camera that can decode a QR code.


Or even lower-powered? https://www.amazon.com/Token2-miniOTP-2-NFC-programmable-Two...

I remember my dad worked at a bank in the 90s and had one shaped like this to enter one of the buildings: https://www.amazon.com/HyperOTP-Time-Based-6-Digit-Services-...


Yeah RSA made these for a looong time.

But if you don't have a phone to program it you'd need a camera or some way to manually enter the data.


FIDO2 Security keys should be considered good "hardware tokens" now , more phishing-resistant than TOTP




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: