Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Haven't signed up, but http://blog.coinbase.com/ does mention 2FA is supported through SMS or an app called Authy. In case the founder sees this, was there any reason why Verisign's VIP app (which has native apps on more devices and seems to be the de-facto standard for banking sites) was not used?


You mean Symantec's VIP app.

Personally, I have no idea why they didn't just use Google Authenticator and implemented OATH/TOTP on their own servers. Relying on a third-party for authentication seems a very bad idea, specially when there's an open algorithm that is essentially just feeding a secret and the current unix time to an HMAC-SHA1.


I hadn't seen it - thanks I'll check it out!




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: