> and if there are biometric sensors that make
> sharing login information impossible (but that
> would annoy people more, not help them).
Just add 2-factor-authentication tied to their phone. You can use Google Authenticator (RFC 6238). > and if there are biometric sensors that make
> sharing login information impossible (but that
> would annoy people more, not help them).
Just add 2-factor-authentication tied to their phone. You can use Google Authenticator (RFC 6238).You can of course set up a new secret & share it with multiple phones at that point. Not sure there’s much you can do to stop that using a software 2FA implementation. If it really matters, then a hardware token is the way to go.
If you can take a photo of the code & re-use it, then you can initialise multiple phones with the same secret.