|
|
|
|
|
by blueflow
739 days ago
|
|
The "replaced laptop" scenario is a full MITM on the hardware. TOTP generally does not protect against MITM. The required TOTP code is, in this scenario, generated by the device in the attackers hand. So the fake could also display it. |
|
The TOTP token here is sealed inside TPM.