<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=3&amp;t=49" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2008-05-20T20:13:57+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=3&amp;t=49</id>
<entry>
<author><name><![CDATA[hrag]]></name></author>
<updated>2008-05-20T20:13:57+01:00</updated>
<published>2008-05-20T20:13:57+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=49&amp;p=55#p55</id>
<link href="https://forum.yubico.com/viewtopic.php?t=49&amp;p=55#p55"/>
<title type="html"><![CDATA[Do you need to use the device in combination with a user...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=49&amp;p=55#p55"><![CDATA[
Q: Regarding my previous question, does you need to use the device in combination with a username and password? If so, then that obviously answers the question - but from what I've read, it's not clear to me that that is the case, I thought you could maybe use the device by  itself as the only authentication factor; however that doesn't make much sense since the data is encrypted symmetrically <br /><br />A: If you don't want to automatically send the pubic ID prefix, you can use a user-supplied identification, such as a username or so. In such a case, only the OTP part is sent (32 characters = 128 bits).<br /> <br />If you want a two-factor login, then you also request the user to supply a PIN or password. That can be used as a static part to be verified by the server together with the dynamic OTP.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=58">hrag</a> — Tue May 20, 2008 8:13 pm</p><hr />
]]></content>
</entry>
</feed>