Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> You know what? I don't trust Google enough to allow them to lock me out of my own systems, and I'm surprised other obviously technologically inclined people do.

This is a common misconception of Authenticator. It is an open source implementation of OATH which works entirely offline once the initial secrets have been shared.

Using Google Authenticator for SSH accounts (via PAM) does not give Google the ability to lock you out of your systems.

Excluding severe bugs and overly paranoid scenarios, e.g. the entire Authenticator system being a convoluted plan for Google to take over your servers.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: