Timo
My feedback
5 results found
-
1,705 votes
An error occurred while saving the comment
Timo
supported this idea
·
-
716 votes
Timo
supported this idea
·
-
1,048 votes
Timo
supported this idea
·
-
1,519 votes
Timo
supported this idea
·
-
1,641 votes
Timo
supported this idea
·
While I agree that this should be an option, I just wanna remind everyone that the only reasonable attack vector of TOTP is phishing.
Meaning if you never use it and just refuse to authenticate with it, always use your hardware keys instead you are safe.
Provided you store your TOTP credentials in a safe place… or not store them at all after setup – that’s up to you.
Guessing TOTPs is not viable and in any scenario where an attacker gained enough privileges to somehow reach your stored OTP credentials, wherever you store them, you are usually in a lot of trouble already anyways… meaning if it comes that far it doesn’t really matter anymore, you are screwed already.