• TheObviousSolution@lemmy.ca
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    3 days ago

    If the site is compromised, then the hackers could have stolen the TOTP secrets as well as the passwords. How do you think the site verifies TOTP codes? If you reuse passwords while using a password manager, you are asking for it, though.

    • Fiery@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      0
      ·
      3 days ago

      A full hack of every part of the service is not the only way a user’s password could get known to an attacker. Could be MiTM, could be typo-squatted, etc

      If a site is that compromised no measure of auth is gonna help, so little use worrying about it.