|
Two-factor authentication systems are secure because it is very
difficult to obtain possession of both factors. Even if an attacker
manages to learn the user’s password, it is useless without also
having physical possession of the user’s token. Conversely, if the
user happens to lose their hardware token, the finder of that token
would be unable to use it unless he or she can also obtain the
user’s password.
|