3 ms·
In addition to the arguments outlined above, it protects against some attack vectors. If the service gets hacked and the password leaked or they discover the pa
by e_proxus 7y ago
In addition to the arguments outlined above, it protects against some attack vectors. If the service gets hacked and the password leaked or they discover the password in some other way, they still don't have the 2FA token and so can't login.
- snuxoll 7y agoIf somebody breaks into a specific service and is able to dump hashed passwords it’s very likely they also had access to TOTP keys. Since you’re already using a password manager you should be protected from password reuse. Ultimately in this case you are protected from MITM attacks and basic forms of keylogging.
- tialaramex 7y agoNot relevant to scenarios where you stash TOTP long term secrets in a password store, but note that WebAuthn / FIDO doesn't have this problem - the data you're keeping per user to authenticate with WebAuthn isn't a secret, it's not even personally identifiable, a bad guy could add their own credentials if they have write access, but they can't learn anything by examining yours.