|
|
|
|
|
by wolvoleo
3 days ago
|
|
They're better in some ways. They don't rely on a secret with low entropy which is really brute forceable. They can't be used on a phishing site because the URL is part of the secret. Even when you authenticate to a fake site you don't give them the ability to authenticate as you until you change the secret (like you do when you give them your password) They also have 2fa built in. No need for a separate app, entering codes whatever. |
|