[SML] Oh great SML mind...

billn at peak.org billn at peak.org
Fri Jun 24 23:42:07 UTC 2016


> Jerry's talking about two factor authentication.  This means having to log
> in with something you know (your password) and something you have.  Jerry's
> something he has is this little Verisign key, which they oddly don't
> support anymore.  Now, and this isn't just PayPal, but the way everything
> is going, is using your phone as something that you "have"... because
> everyone has a phone.  You're not required to use it (yet).  However, it's
> extremely beneficial.  Someone who wants to hack your paypal account and
> sell it on the dark web would need your password AND your phone --
> something that's unlikely to happen at the same time.

Not everyone has a mobile phone - which is why I asked. I make two or three
long distance calls a year, nor do I play the texting game. So a mobile phone
is just an unneeded expense.

I have noticed an increase in businesses that require a person to register
before making purchases. Part of the registration process is sending an email
message to the customer that has to be used to complete the registration -
e.g. vendor generated key for two factor authentication. But an email message
is different than a text message - which is apparently what Paypal is now
sending.

> Dedicated devices are probably better than text messages, but text messages
> are 1000% better than passwords alone.

No argument there - but text messages are useless if a person cannot receive
them.

Bill







More information about the Stagecraft mailing list