Two Factor Authentication
MK
Dictionary Attacks
Something you HAVE
Something you KNOW
Card Readers
Uses secret embedded in chip within payment card
Time based: pre set secret embedded in App is used to generate a time based sequence of numbers.
Secret supposed to be inaccessible so must HAVE phone.
Unique secret (private key) stored in hardware, write only, not available to user, software on PC, or anything else in the middle (even server).
When button is pressed, responds to challenge sent via USB by signing it and returning signature to "prove" it knows the private key.
If you are going to secure ONE account, make it your email...
Adding more security to your account can keep bad actors out, but it can also keep YOU out:
Even with lots of recovery mechanisms your account is more secure than just passwords!