Just from a UX perspective - security aspects aside - this is worse by a magnitude. Password managers are nowadays a single click in your browser. Use them.
Just from a UX perspective - security aspects aside - this is worse by a magnitude. Password managers are nowadays a single click in your browser. Use them.
Still what I would prefer is a single trustworthy service which does not compromise my privacy for the purpose of advertising. I could use that service to log into any service which would integrate with this single service to get a one-time password to the user on the computer or mobile device they are using.
As the user I would be able to use an mobile app and browser plugins to get the one-time password to conveniently log in with as few steps as possible.
This is not true, clicking a link in an email, or copying a number from an sms is much easier than first logging into my password manager, finding the entry and then copy it into the field.
Also, this also works for apps as well, not just the browser.
Besides, password manager usage might still be quite low. So what the writer advocates is not less secure than having a single password for almost all their websites, like most people have.
But either way it's much more preferable to waiting x minutes for your authentication link to appear, and then having to copy and paste. The fact you have to wait an indeterminate amount of time for your auth email/sms to come through means it's a totally sub-standard solution, bordering on the ridiculous.
On websites that I've enabled 2FA on, I let LastPass autofill (no clicks) and pulling up Google Authenticator on my phone is what takes time.
The problem with using SMS as your only authentication is, what do you use for your second factor? I suppose a PIN would work.
SMSes are also trivial to intercept: imagine the national telco silently routes some login SMSes that were going to a number on a list to the local internal security agency. The user just gets no SMS (or a code that doesn't work), assumes something went wrong on the network, and asks for another one. Meanwhile the "baddies" have logged in already and snaffled up the information they want.
What I want is to be able to use Google Authenticator as my only authentication, plus a PIN for slightly sensitive sites and a long password for very sensitive sites (and to disable my phone from a distance).
This has not happened, and if it ever does it probably won't look anything like what the author proposes.
I'm interested in a password manager that works seamlessly on Android.