I'd love the have a software token for windows phone. The only reason I still have my android tablet is for the software token app. It would be much easier for me to have it on the phone I use everyday.
I'd love the have a software token for windows phone. The only reason I still have my android tablet is for the software token app. It would be much easier for me to have it on the phone I use everyday.
can i have it ?
New PS4 player here with a windows phone! I've learned not to hold my breath about apps not coming to WP8, but this would be awesome.
Let's set aside the fact that the app wouldn't even have to know that algorithm (all you need to do is have it tell the server "I am a new authenticator, please generate a seed value for me"). "Taking a lucky guess at the seed"? If you've got that kind of luck, then you'd better hurry up and get to Las Vegas before they find out and ban you for life.They would never work with the community to make this happen, and there's a very good reason why not too. These authenticators work on the basis of a seeded random number string, so to build an app, you would need to know the algorithm they use. By knowing the algorithm and taking a lucky guess at the seed, you would as a result have the tool required to crack the two factor authentication completely... for anyone's account.
There's plenty of one-time password algorithms that are already publicly known. RFC 6238 is used in everything from Amazon to Wordpress, OPIE is included in FreeBSD by default...hell, even Blizzard's two-factor authentication has had its algorithm figured out. As long as the algorithm doesn't call for an incredibly stupid seed (say, an unsalted MD5 of a randomly chosen dictionary word), knowing it won't necessarily give you any sort of advantage.
So you found out that the secret seed value is generated by firing photons into a beam splitter. How exactly is that going to make it any easier for you to guess what the seed value for a given authenticator is?
|
![]() |
![]() |
![]() |
|
Cookie Policy
This website uses cookies. If you do not wish us to set cookies on your device, please do not use the website. Please read the Square Enix cookies policy for more information. Your use of the website is also subject to the terms in the Square Enix website terms of use and privacy policy and by using the website you are accepting those terms. The Square Enix terms of use, privacy policy and cookies policy can also be found through links at the bottom of the page.