hacked The difference between two-factor and two-step authentication. No lengthy article this time folks, just a flow diagram to demonstrate the differences between two-factor authentication and two-step verification. (full size) Why isn't an OTP via SMS a 2nd factor? At first glance, the mobile phone appears to be "something we have" (one of 3 factors necessary to be multi-factor), but that's not quite true. The device itself isn't key to successfully authenticating, but rather the OTP delivered to it. If it were truly a 2nd factor, it would be impos
aes How secure is #Roboform? The 5 minute challenge. TL;DR - Your master password is sent to Siber Systems and the mobile applications are insecure. Described by its creators, Siber Systems, as "completely secure using military grade encryption", Roboform has been knocking about since 1999. Now, I have a rule when testing password managers. If the vendor describes it as "military grade" or "completely secure", I'll set aside 5 minutes to demonstrate why that's never, ever true. Solid security is a mixture of security & usability; a balancin