Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
Two-Factor Authentication for VFP
Message
De
27/10/2022 14:38:41
John Ryan
Captain-Cooker Appreciation Society
Taumata Whakatangi ..., Nouvelle Zélande
 
 
À
27/10/2022 02:30:06
Lutz Scheffler
Lutz Scheffler Software Ingenieurbüro
Dresden, Allemagne
Information générale
Forum:
Visual FoxPro
Catégorie:
VFPX/Sedna
Divers
Thread ID:
01685145
Message ID:
01685160
Vues:
49
Hi Lutz,

>>While I count the kind of 2FA you do as data gathering by google and adding an external point of failure, also it exposes your mobile even more to google - it nicely connects the phone to the app, usage of the app by owner of the phone and so on, data you might freely hand to google or not (You will not believe what one can read from this data), others might think different.

What you're saying is true for many of the other implementations out there that use online APIs to generate QR codes and validate the entered codes. However:

Try disconnecting your Google Authenticator device from mobile and internet. Google Authenticator still scans the QR code and generates the validation code. It appears that Google Authenticator is a simple local app that creates an account on the device when you scan the QR code, then creates the validation code every 30 seconds while open. You can even block network access completely in settings; still works fine AFAICS.

AFAICS the only data gathering point connecting app, user and secret code would appear to be the QR code that gets generated locally in this implementation, to be displayed under app/customer control.
"... They ne'er cared for us
yet: suffer us to famish, and their store-houses
crammed with grain; make edicts for usury, to
support usurers; repeal daily any wholesome act
established against the rich, and provide more
piercing statutes daily, to chain up and restrain
the poor. If the wars eat us not up, they will; and
there's all the love they bear us.
"
-- Shakespeare: Coriolanus, Act 1, scene 1
Précédent
Suivant
Répondre
Fil
Voir

Click here to load this message in the networking platform