4 ms·
Nothing against TOTP per se, but plenty enough against Google Authenticator and its typical use cases. If you log into a website on your phone and use an authen
by nukeop 8y ago
Nothing against TOTP per se, but plenty enough against Google Authenticator and its typical use cases. If you log into a website on your phone and use an authenticator running on the same phone, it's not 2FA, it's just two passwords.
- AgentME 8y agoIf you're reusing passwords, it's still better. Obviously it would be better to not reuse passwords, but in general it seems to be easier to encourage users to do 2FA than to not reuse passwords.
- vinay427 8y agoThis depends on your threat model. Imagine someone looking over your shoulder while you type in your password and TOTP token. Without TOTP, they would be able to log into your account on a different device without having your current device. With TOTP, they would need some way to get the correct token when they login, which is much more difficult and more easily noticed by you.