In this episode I'm joined by Luke Walker who is a Solutions Architect at Yubico, the company that creates security hardware tokens such as the YubiKey.
Security is a big deal in for both end users who are supplying data and developers who are working to keep that data safe. Luke and I spend some time in this episode discussing some of the various two-factor authentication (2FA) mechenisms that can be implemented in web applications and where some of these mechenisms fall short. In addition to things like TOTP, SMS, we also dive deep into the FIDO and FIDO2 protocol which Yubico implements and is pushing as a web standard.
A brief writetup to this episode can be found via https://www.thepolyglotdeveloper.com/2019/03/tpdp-e25-securing-applications-second-factor-authentication/