• killingspark@feddit.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    This. This so much. Password+Totp based login is just two passwords where one is more annoying to use.

    • BCsven@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      1 day ago

      Not if your TOTP codes are generated by another device, then the attacker needs your password, plus the device holding the key for TOTP. If you use it on your phone and authenticator is your phone then a theif has everything when they steal your phone.

      Hardware key for TOTP is a better 2FA method as its totally separate from your PC or phone

      • TheObviousSolution@lemmy.ca
        link
        fedilink
        arrow-up
        0
        ·
        1 day ago

        If you can get at a password by hacking a website, I wouldn’t be holding out hope that they couldn’t then steal the TOTP secret.

      • killingspark@feddit.org
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 day ago

        As long as the default recommendation is to use authenticator apps on your main device I’ll see this as a “could be good if implemented correctly, which it isn’t, so it isn’t good”