Hacker News new | ask | show | jobs
by dns_snek 658 days ago
> I'm sure any smartphone-based TOTP will do

No it won't. Like the article states, I also believe that phishing resistance is a critical property of 2FA systems. This is something that TOTP will never be able to provide.

We don't need Yubikey the brand, but we do need security keys (i.e. FIDO) as a concept.