• Natanael
    link
    fedilink
    327 days ago

    TOTP codes can be phished, hardware security keys and passkey can’t

    • Engywook
      link
      fedilink
      027 days ago

      I doubt that anyone that doesn’t use “password” as a password and who knows what 2FA is could be easily subject to phishing.

      • Natanael
        link
        fedilink
        327 days ago

        It literally just takes a slightly different domain name. Lots of infosec pros have been phished when not paying attention