I built a platform to share SMS Multi-Factor Authentication codes
I built a platform to share SMS Multi-Factor Authentication codes
Hello there HN! I just wanted to share with you a product I've been working on for a while. The product is called GetMyMfa and is accessible at https://get.mymfa.io. The objective of this project is to allow organizations to safely and easily share Multi-Factor Authentication codes for their Quality Assurance and Apple App Store review processes. *Where the idea came from:* I am currently working with multiple customers in the FSI domain (Financial Services Industry) and I am often required to perform tests in production and staging environments with multiple accounts. As production and staging accounts, these accounts are generally required to have at least an SMS 2FA system in place. When performing tests in such sensitive accounts, a single individual usually owns all phone numbers linked to these accounts and shares received MFA codes via a phone call with the various people performing tests in these accounts. I believe this represents a security concern and a bypass of the Multi-Factor Authentication principles. In addition, when submitting iOS applications to the App Store, Apple performs a human review process in which they need to login to the application. When MFA is enforced for all production accounts, Apple rejects the application unless a way is implemented to allow them to login. This often leaves developers with two options: Develop a front-end only demonstration mode, or bypass the MFA mechanism for a specific account. *Therefore, the project aims to:* 1. Allow organizations to rent virtual phone numbers and have their SMS MFA codes be displayed in a private web interface; 2. Organizations have fine-grained access control allowing them to control who can access their virtual phone numbers MFA Codes; 3. Access granting to virtual phone numbers can be time-based. *On the security perspective, I aim to allow businesses to:* 1. Avoid spending time in building a security login "bypass" (and all the security issues that often come with it); 2. Avoid building a "demonstration" mode exclusively for Apple on their mobile applications; 3. Avoid using public websites with public phone numbers accessible to anyone. What do you think? Would you use such product for your business in order to safely manage SMS Multi-Factor-Authentication sharing in production accounts? I would love hearing your feedback on the pros and cons you see about this product. All the best
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Incorrect prediction on native model
Similar products
SMS Multi-Factor Authentication testing made easy
Auto2FA – Autofill SMS 2FA codes anywhere
SMS to Slack streamlines receiving 2FA codes for teams who share logins
Unified Multi-Factor Authentication
Elixir Coherence – Authentication Similar to Ruby’s Devise
beesly – a PAM authentication microservice
Tailscale Authentication with Traefik
Bifrost MTLS Authentication
Satellizer – Authentication for AngularJS
Gondalf – Go microservice for authentication and authorization