Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My duo workflow was figuring out I can request an SMS OTP and read the OTP code as a notification on my laptop instead of unlocking my phone and confirming via the app. Hopefully they get volume pricing on texts.


This kind of workflow is probably against your workplace's rules. This bypasses one of the protections meant through something like a Duo app locked behind a device password screen; which is that even if your laptop is logged in and your password manager is running, a bad actor still couldn't get into protected things if they don't know your phone passcode.


If someone is relying on Mac+iPhone users disabling a convenient and enabled mostly by default feature then they’re doing it wrong.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: