▲ | anonymars 9 days ago | ||||||||||||||||||||||
I assume it's a phishing scenario, given the note about password managers. Evil site spoofs the login page, and when you attempt to log in to the malicious site, it triggers an attempt from the real site, which will duly pass you a code, which you unwittingly put into the malicious site | |||||||||||||||||||||||
▲ | LoganDark 9 days ago | parent [-] | ||||||||||||||||||||||
TOTP is vulnerable to the same attack, though. If you are fooled into providing the code, it doesn't matter whether it's a fresh one to your email or a fresh one from your authenticator. | |||||||||||||||||||||||
|