Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: Lazamataz
Many conservatives post their more controversial takes here because the old-school security allows greater anonymity. Even I say things on FR I would never put on X - where I am a big consumer of content but post almost nothing.

A lot of FR veterans would not be willing to trust even this site with a phone number.

29 posted on 03/16/2025 6:33:15 AM PDT by Mr. Jeeves ([CTRL]-[GALT]-[DELETE])
[ Post Reply | Private Reply | To 1 | View Replies ]


To: Mr. Jeeves

You don’t have to give MFA your phone number if it’s set up right.

The way I’ve set it up - the app generates a unique code representing your username and password, that is 512 bit encrypted, and creates a QR code from it. You scan the QR code into the authenticator app on your phone, and it sends the combined QR+emei encrypted in the other direction.

This way, your phone doesn’t even know what the code does, and the website doesn’t have your phone number.

If you unlock your phone while the authenticator app is waiting for MFA, the app recognises that as proof it’s your phone and biometrics. Sends a message to the MFA server, which then sends “yes, it’s him” to the website.

But when you log in, the authenticator service broadcasts the mfa challenge and only one phone can reply to it.


207 posted on 03/16/2025 10:31:57 AM PDT by MalPearce ("You see, but you do not observe" - Holmes to Watson, A Scandal in Bohemia)
[ Post Reply | Private Reply | To 29 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson