hacked The difference between two-factor and two-step authentication. No lengthy article this time folks, just a flow diagram to demonstrate the differences between two-factor authentication and two-step verification. (full size) Why isn't an OTP via SMS a 2nd factor? At first glance, the mobile phone appears to be "something we have" (one of 3 factors necessary to be multi-factor), but that's not quite true. The device itself isn't key to successfully authenticating, but rather the OTP delivered to it. If it were truly a 2nd factor, it would be impos
identity Does Two Factor Authentication Actually Weaken Security? This article flies in the face of general consensus. As you're here, you either share this view or you're questioning my sanity and/or logic. Adoption Rates Ultimately, the success of any new technology hinges on the end-user. Trouble is, 2FA isn't new... we've used it in various contexts since the 1960s. An ATM machine for example, requires your PIN (something you know) and your card (something you have). When it comes to web-based authentication however, I'd argue it's actually an