• Natanael
    link
    fedilink
    211 hours ago

    TOTP codes can be phished, hardware security keys and passkey can’t

    • Engywuck
      link
      fedilink
      19 hours ago

      I doubt that anyone that doesn’t use “password” as a password and who knows what 2FA is could be easily subject to phishing.

      • Natanael
        link
        fedilink
        23 hours ago

        It literally just takes a slightly different domain name. Lots of infosec pros have been phished when not paying attention