• Natanael
    link
    fedilink
    arrow-up
    3
    ·
    1 month ago

    TOTP codes can be phished, hardware security keys and passkey can’t

    • Engywook@lemm.ee
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      1 month ago

      I doubt that anyone that doesn’t use “password” as a password and who knows what 2FA is could be easily subject to phishing.

      • Natanael
        link
        fedilink
        arrow-up
        3
        ·
        1 month ago

        It literally just takes a slightly different domain name. Lots of infosec pros have been phished when not paying attention