Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You would need a OTP for every one you wanted to talk to. If I had a OTP for every https site I visit, I'd need hundreds. Facebook would need hundreds of millions. They're not going to be mailing out USB sticks on a weekly basis.


You need an RSA token for each server you talk to as well. It's not a replacement for asymmetric cryptography.


You'd "need" (in the handwaviest sense, because nobody had designed a crypto token based on one-time pads here) OTP content for every authentication attempt.


"They're not going to be mailing out USB sticks on a weekly basis"

Mailing? That's not secure enough.. You have to go to Facebook HQ and get your weekly OTP. Daily if you post a lot of images =)




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: