I might not get everything right, but aren't they proposing "kind of" a keylogger as a security solution? Even the idea of using a technology for which others build products to fight against seems a bit strange.
Now, admitting that everyone will use it in good faith, I'd like the fact that, by itself, it does not add another thing you need to do as a user to authenticate. But, as Paul said in his article, I only see it used as a trigger for other security measures.
"As it stands now, unloq limits itself to a single email for a single user." -> We do offer the option to create additional profiles on others email a user might have.
"that phones in the hands of real users are not a reliable means of identification" -> We do agree that phones by themselves are not secure enough. Currently we do offer the option to add a secondary PIN on each profile, but we are thinking to enforce it to the application level.
First of all, thanks for all the great feedback. We’ve just launched in beta and we are striving to make UNLOQ the simplest authentication system. We know that we have a long way ahead of us so we appreciate all the feedback. Here’re a few answers to the comments I’ve seen above:
1. We believe it is a two factor: something you have = your phone; something you are = you’re fingerprint (for the phones that comes with this option and it is enabled); something you know = you’re PIN (you can set additional PIN’s on your profile).
2. Regular two factor provides you with a code to insert in the browser after you authenticated with username and password. We make use of two channels in order to authenticate a user: the browser used to provide the identity and the service’s server - UNLOQ server - device to provide proof of identity. We believe that this makes the system harder to break through man-in-the-middle type of attacks.
3. We know we still have to work on user experience, but entering just your email and then approving on the phone the request seems easier than entering the full set of credentials followed by another security code (as 2fa proposes)
If we start by defining a mean person as one looking for either win - lose or even more, no win - lose (aka, being mean for no reason), I think there are several points for which people are less mean in the startup world and being mean give you less chances to succeed. First of all, I believe that being in a startup is less about “fighting” for an existent market (where someone needs to loose in order for the other to win), but about creating new value and trying to capture the most of it. Founders are (should be) more inclined to think about win-win solutions so that the adoption is high. Secondly, compared to the corporate world, in a startup the focus in on creating value, versus protecting positions and internal politics. On the other side, public profiling and feedback incentivize founders to be at least careful about how they reflect to the world. Nonetheless, being at the beginning of a road, they are more inclined to be nice in order to attract and retain customers & employees.
Without saying that there’s no meanness in the startup world, I would agree that the degree of kindness is higher here than into the corporate world.
Now, admitting that everyone will use it in good faith, I'd like the fact that, by itself, it does not add another thing you need to do as a user to authenticate. But, as Paul said in his article, I only see it used as a trigger for other security measures.