Very interesting, thanks for the article. I was wondering why more projects weren't taking advantage of OTP keys, which offer obvious benefits. YubiKey works with LastPass also. It would be interesting to know if this really improves the security - e.g. when logging in to your mail account in an Internet cafe (which normally is so insecure it almost hurts). In particular, it seems that it's possible to disable or circumvent the OTP requirement for logging in. What is the point of using it if it isn't made obligatory?
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds