Supporting multiple devices is a hard problem. We worked for a long time to enable it. Not Bitcoin protocol specific, but some words about our asymmetric key based multi-device solution here; https://www.mepin.com/lost-device/
HN user
markkum
Founder & CEO of Mepin / Meontrust Inc. Serial entrepreneur, serial father, cereal lover ... password hater.
www.mepin.com
Funnily; the reason to outsource is exactly about not putting all your eggs in the same shared basket. You outsource the 2nd factor and keep the first factor (passwords) in-house. Implementing everything in-house is a "same shared basket".
I can use similar arguments; a user can be tricked to enter an OTP to a phishing site. For that the hacker does not need to time the attack to the same second, so it's much much easier attack for the hacker.
'No 2FA' is the real silly one here. Any 2FA is so much better than no 2FA, and usability has been a big issue so far in 2FA adoption.
Note that MePIN does not collect or need user's phone number, e-mail address or any other user information. You can use MePIN fully anonymously.
Unfortunately there are several cases where users have entered an OTP code for another user. The recent high profile case was with World of Warcraft's OTP.
Don't want to argue, but yes it would. It would stop the user for a second, giving time to the brain to process for a while what's going on.
This is now fixed. Thanks for the kick.
First; the user does not have to care about OS, browser, ip address or location. Though those can be shown to a user if the service provider wants.
Authorization requests can only be initiated at the back-end by authorized service providers and only for users who have linked their MePIN app with that specific provider. Though of course login verification could be initiated with stolen username/password, which would then alert the user for verification.
Now the added benefit here is that with MePIN the user would immediately know that her username and password is at wrong hands if she receives a login verification request while not actually performing a login.
So obviously the user should not authorize unexpected requests. You would not authorize a login if you are not actually performing a login, etc. Concerned users can additionally set up a personal PIN code in the app.
Lack of good usability is currently hampering 2FA adoption, we are working hard to fix that.
Of course user behavior has to be considered. The MePIN app does allow the user to set up a personal PIN code, so an authorization would then require the PIN code and a tap.
The solution is based on Public Key Infrastructure (PKI). Each authorization must be signed with the user's private key. The app is managing and protecting the keys and certificates, so user does not have to figure out key/cert management. Some info here; https://www.mepin.com/technical-overview/
Working on it.
The service is distributed and hosted at 3 continents with 3 different hosting providers, so we take this seriously.
Other than that; You own your users and user database. No user data is stored at MePIN servers.
It's easier because you only need to tap the app to verify. No need for OTP codes, though OTP is a fallback if your device is offline.
This is the London I remember from early morning July 8th, 2005, the morning after the bombings. Was walking around to find a ride to the airport, couple of blocks from the double-decker wreck. Wish not to experience the same again.
Well, yes and no. On iOS you can somewhat rely on keychain, but when the device is jailbroken all the local "simple API" security is gone. Generic Android doesn't really have anything that I would call secure, so there a serious solution needs some heavy lifting.
And yes, the pals at AuthenTec had some cool biometric and related stuff when I worked with them :), before they were swallowed by Apple. I'm certainly looking forward to what Apple will launch ... but a fingerprint does not magically solve all the issues.
The cool generalized version does exist :). Check out https://www.mepin.com/
We've got RSA 2048 keys on iOS, Android and a separate smartcard USB key, and do 2-factor login and transaction authorization with a simple tap in an app + optional direct login without a password + trusted messaging. Available as an app or an app SDK.
What I'm wondering is whether Twitter is actually protecting the private keys? That's the real tricky part.
Hi, a new developer section for the site is in the works. Stay tuned.
If you want something better for your site; check out MePIN https://www.mepin.com/
You can sign in without username and password to OpenID enabled sites with your smartphone and Mepin; https://www.mepin.com/
Here's an example Neko.io message for you;
"I'm on a meditation trip in India. If you really need to bother me, here's my travel schedule and emergency number; https://neko.io/m/g4hF/xcjZq85lyL9TTAjefE1GLw/xGf_TME2-G9YRl...
Neko.io is a utility. People post links to social networks all the time. The above link might look long and scrambled, but most services are shortening it automatically.
Not really. Clear text messages on Fb Friend List or G+ Circles are indexed and affects your profile (towards advertizers and others), whereas Neko.io messages are encrypted and truly private. Also, the Neko.io friend list spans across any and all social networks, so you would not need to maintain lists, circles, groups, flocks, etc in various services.
We (Meontrust Inc, the provider of Neko.io and Mepin.com) would be happy to provide public key crypto (PKI) for such a service or project. Neko.io authentication, i.e. Mepin, is based on PKI.
Unfortunately this is true for now. Obviously we are going to launch other device support and means to sign in. I hope you left a vote at the site about your preferred device platform.
Clickable links;
Check out https://neko.io/ ... we are scrambling/encrypting messages into URLs which you can then share on Facebook, Twitter or where-ever.
Yes, you can post the secret message links to your Twitter account.
Many thanks for the feedback! You get an Access Code from the site, which you should enter on the Mepin app, which then logs you in. Try again, it's cool, thanks!
What drives me to start ups is something like self-expression. There's no-one else's expectations to worry about, just my own big ones (which exceeds the investors' :-). The feeling when those expectations are even partially fulfilled is amazing. And every little step forward feeds the feeling, whether it's finishing yet another investor pitch deck revision to walking out from a successful meeting to the big ones like signing a customer and maybe even exiting.
With regards to spouses; I've so far been one of the lucky one's to have a supporting spouse and kids whom have gone through the ups and downs with me. It's not easy for them, but I suppose they also partially feel the excitement and anticipation of a breakthrough.
Nowadays it might also help that they know there's a reward for them too. After my first exit I bought and renovated a house and after the second we took a few weeks luxury around the world trip. Which leads me to the question for you Christeen; What was your reward? A chance to start your own startup?
Passwords are painful for the users, and not good for service providers either; https://www.mepin.com/2011/09/26/7-problems-with-usernames-a...
Support OpenID!
Having done business in China and knowing a little bit how some of the good people there think; my bet is that the square pattern(s) which looks like Voronoi diagram are just a Chinese version of the Crop circles http://en.wikipedia.org/wiki/Crop_circle. They like to do things in major scale in China.
Couple of the pictures were clearly geology/mining related and one is a military training area. No biggies.