The more I think about it, it seems to me that the Internet itself really needs to be a two-channel system. If communication has two separate physical channels then it becomes much easier to ensure security.
The more I think about it, it seems to me that the Internet itself really needs to be a two-channel system. If communication has two separate physical channels then it becomes much easier to ensure security.
w.r.t:
> I also foresee potential issues with data corruption on keys, and multiple-keys getting out of sync (e.g. work vs home).
and
> Also, it just doesn't seem as secure as an SMS code b/c the SMS code doesn't exist but for a short window of time and is transmitted by a completely separate communications channel
Are you talking about U2F? There are no synchronization issues there. And it is more secure than OOB codes because they can be phished. For U2F your browser is in the loop, and the origin to which you are authenticating is folded into the signature. Thus it is detectable by the RP if the signature was generated on a phisher's non-legitimate website.