Remix.run Logo
malfist 9 days ago

Whole heartedly agree. It's not more secure if you only use the second factor of two factor auth.

LoganDark 9 days ago | parent [-]

Codes that are provided on demand by a service will always be far less secure than proper TOTP. Because in the case of proper TOTP, no secret ever leaves the service after initial configuration, but in the case of discount 2FA through email or especially SMS, a fresh secret has to be delivered to me each time, where it can easily be intercepted by all manner of attacks.

malfist 9 days ago | parent [-]

Absolutely, a shocking about if email traffic is still unencrypted. Any hop along the SMTP way could be compromised