|
|
|
|
|
by crazygringo
539 days ago
|
|
Good point about it being similar to passkeys. But why would it be better to use passkeys? Because don't sites with passkeys generally still allow you to fall back to password, since it's common for people to lose their phone and then lose their passkey? Whereas sites with 2FA obviously don't, and have more complicated/secure recovery mechanisms? So seems to me like 2FA (TOTP's) are currently vastly better in practice? |
|
If an adversary can successfully phish someone, they can often also trick them into providing TOTP codes or approving push notifications. However, TOTP remains significantly better than the alternatives, as it prevents credential stuffing attacks and SMS-related compromises while potentially limiting any account breach to a single session.