mtbc: photograph of me (Default)
Mark T. B. Carroll ([personal profile] mtbc) wrote2016-08-02 07:13 pm

Two-part security codes

By e-mail or snailmail I occasionally receive a letter that tells me two pieces of information that I need to type into something else, e.g., for voting via a website.

I don't know what the point is of dividing the code into separate components. From a security point of view it seems to be just one code: they send me the components together and I use them together.

Is there typically some other use case that I am not seeing, in which the components become usefully separated? Are the organizers just trying to make the security look better than it actually is?
damerell: NetHack. (normal)

[personal profile] damerell 2016-08-03 11:53 am (UTC)(link)
In some cases, one is a serial number which can easily be discovered by anyone who works on $foo, the other is essentially a password.
emperor: (Default)

[personal profile] emperor 2016-08-09 06:11 pm (UTC)(link)
I think they can't be arsed to update their username/password logic, and so that's what the two codes are, effectively.