Hacker News new | ask | show | jobs
by account42 1149 days ago
Any attack that can intercept TOTP codes (= some kind of MITM or local device compromise) can also request the unwanted actions with the IP of your device. All this does is prevent lazy attacks.