Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> You live in a free market, so move your business to someone who you think takes security seriously.

Adorable. Please show me a bank, utility provider, brokerage, widely-used P2P money transmission service, and phone provider that each offers WebAuthN (without a mandatory fallback to SMS-2FA).

There is absolutely no "free market" for authentication methods: Everybody does almost exactly the same thing, as authentication probably does not even make their top 10 business priorities.



I don't know where in the world you are but...

Bank: Most banks in the UK use an industry standard Chip Authentication Program - which uses the bank card's chip rather than SMS 2FA https://en.wikipedia.org/wiki/Chip_Authentication_Program

P2P Money: Coinbase https://www.yubico.com/gb/works-with-yubikey/catalog/coinbas...

Brokerage: Vanguard https://www.yubico.com/gb/works-with-yubikey/catalog/vanguar...

It would be a bit odd to have a mobile phone provider who doesn't support SMS. But looks like Vodafone is hiring someone with WebAuthN experience https://opportunities.vodafone.com/job/Dusseldforf-Solution-...

Hope that helps.


> I don't know where in the world you are

Ah, your earlier statement ("you live in a free market") implied otherwise. Maybe something worth considering before asserting that there is free market choice in all of these industries.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: