3 ms·
Phishing is a top threat to users and enterprises both. OTPs, whether from SMS or not, can be easily phished as well as passwords, while U2F cannot. So the answ
by mikecb 10y ago
Phishing is a top threat to users and enterprises both. OTPs, whether from SMS or not, can be easily phished as well as passwords, while U2F cannot. So the answer seems fairly clear.
- duaneb 10y agoOTPs must be phished and then used very rapidly. The ROI for a successful phishing is much lower: a database of old OTPs is much less useful. (I'm sure you could use that to break the secret, but it's definitely not storing the secret.)
- mikecb 10y agoTrue, but not difficult.
- datguacdoh 10y agoOnly if you are using TOTP. If you're configured to use HOTP, then that phished credential is much more valuable.