Authy (YC W12) launches two-factor auth as a service
techcrunch.com
techcrunch.com
They make the X-Ray Android vulnerability scanner (http://www.xray.io/)
> queue jokes about Microsoft security
Cue, not queue.
Now, sure the password on that knitting forum might be the same as your bank online account. But the point is that only websites where your account is sensitive needs to add two-factor authentication.
I should have phrased my comment above another way: the solution to password re-use is not to add two-factor auth to a knitting forum, but to add it to the bank website, email provider, etc. anywhere your account's safety matters.
(I was thinking more from the point of view of the user: if they start to get worried about their accounts getting hacked, two-factor auth on the forum is not the solution, a password manager is)
But I would especially want this if the TFA is running on a separate system from the main CPU in my smartphone, only sharing radio/networking hardware at most. This wouldn't be foolproof, but if my smartphone OS company can patch security holes in a timely manner and deliver the patches on-air, then this is good enough for me.
If Authy can deliver the 2nd factor automatically from my iPhone to my other devices through Bonjour, I will rave favorably about them to everyone who will listen.
Remember their short-lived QR code-based logon system?
http://www.theverge.com/2012/1/17/2714263/google-experiment-...
http://www.zdnet.com/blog/igeneration/googles-qr-code-log-in...
Horrifying. There are so many better ways of providing zero interaction auth that is secure: BrowserID, NFC (smartphones that can thus do asymmetric encryption), the QR experiment Google did.
Even if you just tweaked your idea to do something along the lines of what Google did... You go to a browser, type gmail.com, enter your email address. They push an event via GCM and your phone asks if you trust the computer that just asked for auth. You click "YES". Similar flow, but no where near as horrifying.
I'm horrified that people jump to such stupid conclusions. There is no need for one machine to query credentials of the phone or vice versa. The browser just sends out a signal and the phone can supply the 2nd factor to the server.
I already have FOUR two-factor-auth apps on my phone, each with multiple tokens:
RSA
Blizzard
SWTOR
If I can add all the above tokens into your app, I would consider using it. Otherwise... well, good luck with that.
Unfortunately its not technically possible for us to allow you to install RSA, Google in our App, as that would mean we would need access to their private seed, which they don't allow.
Here is an example of a third party Blizzard app: http://code.google.com/p/winauth/
Would make an interesting follow-up to understand how they pitched TC / how the DropBox timing impacted publication (if at all). Either way thanks for responding.