S7 will be retired or extended with access control. TOTP apps don’t work for edge cases like broken phone. Dedicated token devices get lost. SMS will continue being the main solution for 2FA.
I agree, it’s not a perfect system. Even if you do have multiple devices - you may be locked out if you lose your phone while traveling, can have multiple failures.
Although I don’t know what is remotely secure and is elderly friendly. Email or SMS 2FA would have been the closest in mind, but it’s not secure, and plenty of elderly struggle with both.
Nah what we need is good privacy-focussed companies getting into the public IAM space.
You know how you can sign into stuff with your Google or Facebook account? And get a 2FA push to your phone?
Like that. Except by a company with a shred of ethics and morality. Like Proton.
I do also think that we all should have a cryptographically secure federally issued identity for official uses such as signing documents or signing into financial accounts and other things that must use your official identity, and not an online pseudonym. Like SSN but on a smartcard. Basically CAC or ECA but for general civilian use.
Proton is already used for identity management: OTP via email. They’ll implement OAuth if there’s enough demand for it. A company’s purpose is to be profitable, ethics side is largely irrelevant.
Many countries already have digital government ID: Australia, Estonia, Russia.
A company’s purpose is to be profitable, ethics side is largely irrelevant.
Maybe so, but companies such as Proton’s biggest asset is their reputation…a reputation of being privacy-focussed. Without that they are nothing, and they know that. As a result, they try to live up to that reputation as well as possible.
Being as it was started by Sir Tim Berners-Lee (among some of CERN’s other founding fathers of the web) is just icing on the cake.
S7 will be retired or extended with access control. TOTP apps don’t work for edge cases like broken phone. Dedicated token devices get lost. SMS will continue being the main solution for 2FA.
You can use TOTP with multiple devices. For example with an app on your phone and something like KeePass on your laptop/desktop.
Still not convenient since you don’t walk around with this in your pocket - but it doesn’t have to be just one point of failure.
What about people who only have one device? Kids, elderly, people with only work computer.
I agree, it’s not a perfect system. Even if you do have multiple devices - you may be locked out if you lose your phone while traveling, can have multiple failures.
Although I don’t know what is remotely secure and is elderly friendly. Email or SMS 2FA would have been the closest in mind, but it’s not secure, and plenty of elderly struggle with both.
Nah what we need is good privacy-focussed companies getting into the public IAM space.
You know how you can sign into stuff with your Google or Facebook account? And get a 2FA push to your phone?
Like that. Except by a company with a shred of ethics and morality. Like Proton.
I do also think that we all should have a cryptographically secure federally issued identity for official uses such as signing documents or signing into financial accounts and other things that must use your official identity, and not an online pseudonym. Like SSN but on a smartcard. Basically CAC or ECA but for general civilian use.
Proton is already used for identity management: OTP via email. They’ll implement OAuth if there’s enough demand for it. A company’s purpose is to be profitable, ethics side is largely irrelevant.
Many countries already have digital government ID: Australia, Estonia, Russia.
Maybe so, but companies such as Proton’s biggest asset is their reputation…a reputation of being privacy-focussed. Without that they are nothing, and they know that. As a result, they try to live up to that reputation as well as possible.
Being as it was started by Sir Tim Berners-Lee (among some of CERN’s other founding fathers of the web) is just icing on the cake.
Proton gives data to governments if requested. Why are you trying to shill it?