Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So now we're carrying around 130 security tokens? Unless you're talking about this in conjunction with a password manager, all the OP's arguments apply to this too.


The token would either have to work with a single-sign-on authority that would authenticate you to other parties (like OpenID, but hopefully easier to use), or it would contain multiple "authentication slots" for the parties that issue credentials. Both things already exist today, although I don't think they are very widely deployed. But certainly companies that deploy something like the RSA tokens have a company-wide single sign in working with them, and there is no reason for that to stay within one company. Both solutions are technically very different from a password manager.


I have several security token apps on my phone. I'm not saying that's the best solution, but it is a solution.


No. It's better. Because somebody can still your password by eavesdropping. But they can't still your token the same way. (Unless the cryptography used is seriously broken.)




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: