|
|
|
|
|
by rustcleaner
645 days ago
|
|
TOTP is so good, it should be treated equally to or superior than phone number or e-mail as a requirement, by regulation, as an option for any site conducting business in US Dollars. E-mail is terrible for secure authentication. Banks have had plenty of time to implement this and haven't. TOTP can eliminate the password altogether, and make login usernames long-lived long TOTP or HOTP codes and I have just solved the terrible passkey problem! |
|
SMS, on the other hand, is an abomination to this very day and should not be used by anyone for anything.