Reply to post:

FIDO Alliance says it has finally killed the password

nobody who matters

"....A smartphone is something that end-users typically already have...."

Errrr, nope, not here, and I think they had better do some wider research - article in the news today that usage of dumb phones is on the increase; more than doubled in the last two years whilst use of 'smart' phones has dropped back. It is reported that 1 in 10 mobile phone users in the UK are using dumb phones (I am not alone!) See https://www.bbc.co.uk/news/business-60763168 for the full article.

".....Virtually all consumer-space two-factor authentication mechanisms today already make use of the user's smartphone...."

Again. nope - the only thing that I use that forces me to 'verify' via a second authentication method does so via my landline - not convenient perhaps as I can't use it when away from home, but I'll be damned if they are having my mobile number!

@fredblogggs ".....and stop answering phone calls if you haven't already (99% of all phone calls are spam and/or scam)."

Mine aren't! In fact, I can count the number of spam/scam phone calls that I have had on my mobile over the last 15 years on the fingers of one hand (and have some spare); largely because I absolutely do not give my mobile number to anybody or any organisation who I percieve as having no legitimate reason for knowing it. I strongly suspect that the people inundated with spam calls are those who are handing out their number to all and sundry, including because 2FA!

Similarly with my email addresses - the only one that I now get occasional spam on is almost certainly because of a breach that occured to an organisation who run web forums, a couple of which I am registered with. The amount of crap is still small however, and almost all ultimately traces back to a single source.

I stillfirmly believe a single very strong password is as good a security as any other. The problem is that vast numbers of people do NOT have strong passwords (and vast numbers of websites and organisations do not force a strong password policy) - educating/forcing the use of strong passwords would be a better way forward - treat the underlying cause, not simply gloss over the symptoms.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon