4 ms·
Wouldn't they also need access to a device that already synced your passwords? That essentially switches your computer to be the second factor, albeit one that'
by bskap 8y ago
Wouldn't they also need access to a device that already synced your passwords? That essentially switches your computer to be the second factor, albeit one that's more easily compromised with malware. And if they already have malware on your computer, you're probably hosed anyway since the passwords have to be decrypted at some point.
If all they managed to do was trick me into entering my master password on a dummy login page, the sort of phish that U2F is designed to protect against, U2F would still keep me protected while OTP wouldn't.