• Engywuck
    link
    fedilink
    1321 hours ago

    Why would I want security based on a device? What security this offers greater than a 64 chars password + 2FA?

    • Natanael
      link
      fedilink
      211 hours ago

      TOTP codes can be phished, hardware security keys and passkey can’t

      • Engywuck
        link
        fedilink
        19 hours ago

        I doubt that anyone that doesn’t use “password” as a password and who knows what 2FA is could be easily subject to phishing.

        • Natanael
          link
          fedilink
          23 hours ago

          It literally just takes a slightly different domain name. Lots of infosec pros have been phished when not paying attention