Comment on Google binning SMS MFA and replacing it with QR codes • The Register
hazelnoot@beehaw.org 11 months ago
I’m confused about how this is supposed to act as a second authentication factor 🤔
Comment on Google binning SMS MFA and replacing it with QR codes • The Register
hazelnoot@beehaw.org 11 months ago
I’m confused about how this is supposed to act as a second authentication factor 🤔
FiskFisk33@startrek.website 11 months ago
A guess/suggestion: a
You have an app with a private key. The qr code contains data encrypted with the corresponding public key. Your app decrypts the data and transmits it to googles servers, proving you are in possession of the secret key.
hazelnoot@beehaw.org 11 months ago
oh so it would just be app-based MFA but without using TOTP. That makes sense