Ask HN: Why no 2-factor authentication for web apps?
https://news.ycombinator.com/item?id=359093More and more I find myself keeping data on webapps (like gmail) that is really sensitive. I don't doubt that someone could successfully impersonate me or steal my identity if they shoulder surfed my password and had intent.
Why is there no open and easy to implement 2-factor authentication system? Is it just because nobody has built one and championed it?
Obviously this won't work on Gmail unless Google implemented it - but maybe this could be the killer app for OpenID (yeah right).