My sugery offers Patient Access. I have a password manager on my Win10 machine and when I log in I receive a code to my mobile.
Patient Access now seems to want to push people to install an Authenticator App.
Pros/Cons/Experiences would be helpful as I don't like IT complication as it too often goes wrong.
Didn't find your answer? Ask the community — no account required.
B
Bob Eager
I personally prefer them, as they are less hassle than waiting for a text.
And it's possible (if they use the MS/Google app) to hack up stuff to authenticate yourself, if you are a nerd!
J
Jeff Gaines
Do you need a different one for each website?
L
L
I prefer to use iOS built in authenticator.
The one time passcode will be auto filled when you signing in into website.
J
Jethro_uk
Some password managers can also generate a 2FA for you, if you can get the "secret" that seeds the code. Although 2FA is looking rather frayed, as passcodes are now being used by the big boys.
Good thing about a *decent* password manager is you can store notes aganst logins. Which is an ideal way to save the emergency codes that can be provided for offline access. Obviously for mission critical stuff a hardcopy of the codes is the final backstop.
J
Jethro_uk
Yes.
Generally they generate a "secret" from your email address and their URL and pipe it into a timed (30 seconds) algorithm. This is why it's essential to have your clock synced.
Somewhere I have a link
formatting link
that lets you create a QR code for an authenticator with custom parameters.
In my current role, I setup 2FA for all the key accounts and screenshot the QR code into a folder and hardcopy print which lives in the CEOs safe. If necessary any account should be recoverable in the event of an authenticator being out of commission for whatever reason.
J
Jethro_uk
Interestingly this was published today. Notice how it effectively deprecates 2FA
formatting link
D
David
On Fri, 03 May 2024 13:17:57 +0000, Jethro_uk wrote: <snip>
<snip>
This caught my eye.
Does this have any implications when you have multiple PCs you use for access to sensitive sites?
No reliance on using the same clock each time?
Not looked into this so far so a drive by question.
Cheers
Dave R
T
Tim Streater
And what might one of them be?
J
Jethro_uk
Without reading into the spec in a detail I don't need to, I would educate a guess that as long as each devices clock produces the code expected for itself, that's enough. The timekeeping requirement is relative, not absolute.
That said not long ago, I was waiting for a new code to be generated as the existing one was only 4-5 seconds from expiring. A colleague said that even after a new code has been generated, the old one works "for a bit".
So there may be some float in the system to account for you getting a code at t+29s and it being entered at t+35s. It[s certainly something I would try to design in to avoid a deluge of help desk calls about the code "not working".
T
Theo
The registration and authentication codes are different for each website (that's the point), but you don't need a different app per website.
The common protocol is called TOTP and is supported by apps like Microsoft and Google Authenticator. But there are many other apps which also implement TOTP and you can use them interchangeably - and there are apps for desktop as well as mobile.
Some password managers include TOTP functionality which means the password manager can generate the TOTP codes as well as store your saved password.
That's usually the downside of 2FA: you need a good channel by which you can reset the account if you lose your authentication device. While this reset process can be a point of weakness, too many online companies just say 'sorry, you'll never have access to your account again' which is not good enough when people lose codes for a variety of good reasons.
Theo
J
Jethro_uk
Amazon, Google, MS, AWS, Zoho, all allow (in some cases "require") the generation of codes for offline use. These are device independent.
I gave up dealing with a lot of very dim people about 5 years ago whose sole reason for not signing up to 2FA was "what if I can't get a signal ?". Which in many cases is really an invented excuse (see also the bus queue vs. single person choice for autonomous cars) that has never ever happened. Certainly not to them.
T
The Natural Philosopher
The only reason I got a mobile fone with wifi calling was that where was living HAD NO SIGNAL. None. Nada. No DTB TV either.
And I needed to receive SMS texts
J
Jethro_uk
Oh I don't doubt there are *some* people that have experienced no signal. I did use to caravan.
However, it wasn't the people who worried about it that experienced it. Another instance of worrying on someone elses behalf.
T
The Natural Philosopher
I worried about it enough to get a mobile I didn't otherwise want.
A
AnthonyL
Somehow I now feel less comforted after reading the comments.
I know security is an increasingly important issue, I just worry about the robustness of the whole system and the inflexibility of getting through to any suppport when something fails.
A
AnthonyL
One might be WinAuth but others may be available :)
formatting link
C
Chris Green
What I find annoying is web sites that require ridiculous levels of security that are quite unnecessary.
I really, really, don't care if argos.co.uk knows my name and address, the whole world knows my name and address. So why do I have to jump through hoops and have an ultra-secure password to buy something from Argos?
Much more important is whether I leave my credit card details with them, no chance - except that I doubt if **their** security is good enough to be sure that my details have been deleted.
T
Tim Streater
Ah, you're talking about a software PINSentry, is that it? Why can't I just use my PINSentry?
T
Theo
No, PINsentry is what Barclays call the card authentication system, generally known as EMV CAP. That's where you put your card in a reader and use your PIN (you can use any EMV CAP reader for that, doesn't have to be Barclays' branded one)
PatientAccess is using TOTP which doesn't use cards, only software. (although there are many implementations, so you can use an implementation with a physical token if you choose to)
Theo
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.