3 ms·
Also, how will sending a new password to your cell phone help? If you are dealing with state sponsored actors, why not assume they can see all text and email?
by jsprogrammer 11y ago
Also, how will sending a new password to your cell phone help? If you are dealing with state sponsored actors, why not assume they can see all text and email?
- Laforet 11y agoA two-factor authentication token to sent via text, not the actual password. That said, I find SMS-based 2FA to be pretty dodgy as well. Cloudflare was hacked once by somebody who managed gain access to an admin's mobile phone by social engineering their telco. If a site does not offer TOTP based 2FA I usually don't bother using it.
- jsprogrammer 11y agoI didn't say the actual password. The page wasn't very forthcoming on all the details, but a 2FAT is typically just a very short, temporary password.
- suneilp 11y agoHow does TOTP compare to HOTP?
- Laforet 11y agoHOTP tokens does not expire with time, so there is a bigger risk of them being stolen from transit/storage and successfully used.
- johncolanduoni 11y agoIf the actor is not sponsored by a state that would have easy access to your telecom (e.g. you live in the US but the attack is from a hacker sponsored by China) this is still very helpful.