Would having one online username+one password+service unique two factor auth code be safe?
Is that what things are moving towards with OpenID, OpenAuth and two factor auth like with google authenticator and similar services?
Is it possible to reverse engineer the user unique two factor auth from the pseudo random auth codes? The sequence is deterministic, right? How many consecutive samples would you need to reverse engineer the hash key?
What are the worst case scenarios involved here?
Is that what things are moving towards with OpenID, OpenAuth and two factor auth like with google authenticator and similar services?
Is it possible to reverse engineer the user unique two factor auth from the pseudo random auth codes? The sequence is deterministic, right? How many consecutive samples would you need to reverse engineer the hash key?
What are the worst case scenarios involved here?
Last edited:
