Hacker News new | ask | show | jobs
by ericalexander3 2360 days ago
U2F > TOTP > Any MFA > no MFA

Why? About 23% of the classified breaches in this data set are due to compromised valid accounts and any MFA would probably have prevented the breach. Often security isn't about out running the bear, it's about out running the person next to you.

data set: https://github.com/ericalexanderorg/SecurityBreach

1 comments

New systems should implement WebAuthn rather than U2F.