top | item 43989856

(no title)

genevra | 9 months ago

What's the actual method that can be easily deployed at scale then?

discuss

order

iamjackg|9 months ago

I'd argue that there isn't one: you have to offer multiple choices. Auth through any TOTP app, Yubi key, pre-generated codes, mailing a physical code generator, etc.

afiori|9 months ago

Email + SMS + generic time-based OTP seems quite enough for imho