@cm0002@lemmy.world to memes@lemmy.world • 27 days agoTake your passkey and shove it where the sun don't shinelemmy.worldimagemessage-square175fedilinkarrow-up1591arrow-down140
arrow-up1551arrow-down1imageTake your passkey and shove it where the sun don't shinelemmy.world@cm0002@lemmy.world to memes@lemmy.world • 27 days agomessage-square175fedilink
minus-squareNatanaellinkfedilink3•27 days agoTOTP codes can be phished, hardware security keys and passkey can’t
minus-squareEngywooklinkfedilink0•27 days agoI doubt that anyone that doesn’t use “password” as a password and who knows what 2FA is could be easily subject to phishing.
minus-squareNatanaellinkfedilink3•27 days agoIt literally just takes a slightly different domain name. Lots of infosec pros have been phished when not paying attention
TOTP codes can be phished, hardware security keys and passkey can’t
I doubt that anyone that doesn’t use “password” as a password and who knows what 2FA is could be easily subject to phishing.
It literally just takes a slightly different domain name. Lots of infosec pros have been phished when not paying attention