Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'd think the biggest draw would be not developer ease as much as end-user ease. This way, an end user with an Authy account would only have to give their phone number out once, to Authy, or install one app from Authy, and automatically be able to use two-factor authentication on any site that supports it. It's like OpenID for the second half of two-factor auth.


Totally agree... site specific TFA apps is already starting to get a big silly. Battle.net, Google, my Bank... three is already starting to be a pain to manage and install.


Give your phone number once to Authy and then to every app that wants to use Authy.


Why? If that's necessary, Authy is doing it wrong. A client app ought to be able to request an auth token that Authy sends to the user without ever having to reveal the user's number to the client app.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: