Phones could allow much higher security if they supported 2 factor authentication. This could be face/fingerprint along with a typed or swiped password. This seems like a simple solution that leverages software that is already implemented. Just make it an added option in addition to the existing one

ETA: Sorry for the duplicate posts, I was getting error messages. Pls use this one.

I am surprised there is confusion about what 2fa is. Here is a simple definition: https://www.microsoft.com/en-us/security/business/security-101/what-is-two-factor-authentication-2fa

    • slazer2au@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      3
      ·
      9 months ago

      For convenience phones don’t always ask for the pin code. That is the other method.

        • Lmaydev@programming.dev
          link
          fedilink
          arrow-up
          5
          arrow-down
          3
          ·
          9 months ago

          2FA is using your password and your phone (for example) to get into an account.

          If someone has your phone and your biometrics/password you’re basically screwed.

          It seems like a really unlikely sequence of events that would lead to this.

          Do you have any sources talking about this happening?

          • Nibodhika@lemmy.world
            link
            fedilink
            arrow-up
            7
            arrow-down
            1
            ·
            9 months ago

            OP is correct 2FA refers to authentication via 2 factors, e.g. digital and pin. Phones use only one, you can unblock them with either a digital or a password, that’s LESS secure than 1FA and much less secure than 2FA.

            The phone itself is not a factor, because every scenario starts with the attacker having access to the phone. If phones had 2FA someone would need to get your digital AND your password to access it, so a lot less likely to happen than having either of them.

            The answer as to why that’s not an option is this would be impractical and people wouldn’t use it. But it would be definitely more secure than current system.

      • guyrocket@kbin.socialOP
        link
        fedilink
        arrow-up
        3
        ·
        9 months ago

        I think the confusion here is that I mean to use 2FA to access my phone, not websites or other hardware.