The principle is familiar to many from online banking: In addition to the user name and password, an additional factor is required that is in the possession of the account holder. In the past, this was often a TAN or iTAN list. Without this second factor, access was not possible even with knowledge of the user name and password. Two-factor authentication implements this procedure in a modern way: The TAN list is replaced by an app on the mobile phone. This app generates time-based one-time passwords (OTP). Each code is only valid for a maximum of 30 seconds. Anyone who has already used online banking with TAN will have no difficulty with this procedure. |