Authify Login Application implements a very secure way of authentication called "two-factor" or "strong authentication" based on one time passwords.
Instead of authenticating with a simple password, each user carries a device ("token") to generate passwords that are valid only one time.
Commercially available tokens look like pocket calculators or key fobs with a display and a keypad. To generate a one-time password (OTP) the user has to enter his PIN into the device.
The authentication is based on two factors: the token device and a PIN ("something you have and something you know").
This is obviously more secure than just a password as an attacker needs to get hold of both the PIN as well as the token device.
In addition, eavesdropping on a password that is valid only one time is of no use to the attacker. On the other hand, the drawback of strong authentication is that every user has to be provided with a token device, this can be quite expensive.
Fortunately smartphones are becoming more and more popular. It stands to reason to use your mobile phone as an authentication token</div> <div class="id-app-translated-desc" style="display:none">Authify登录应用程序实现了一个非常安全的方式称为“双因素”或“强身份认证”的基础上一次性密码认证。
而不是用一个简单的密码进行验证,每个用户携带的移动设备(“标记”),是有效的只有一个时间来生成密码。
市售令牌看起来像袖珍计算器或钥匙链,一个显示器和一个键盘。要生成一个一次性密码(OTP)的用户具有他的PIN输入到设备中。
认证是基于两个因素:的令牌设备和一个PIN码(“你有什么,你知道的东西”)。
这显然不仅仅是一个密码更安全,作为一个攻击者需要掌握的PIN,以及令牌设备。
此外,窃听的密码是有效的,只有一次是没有用的攻击。另一方面,强身份验证的缺点是为每个用户都提供一个令牌的移动设备,这可能是相当昂贵的。
幸运的是,智能手机变得越来越流行。按理说使用您的手机作为身份验证令牌</div> <div class="show-more-end">