Hacker News new | ask | show | jobs
by adam-p 539 days ago
Except that TOTP codes are MitM phishable. U2F with its URL-checking (via browser cooperation) is needed.