3 ms·
It is two factor still. For example, if you need to give a OTP through sms after puting the credentials. It is possible someone stole the credentials and entere
by orestarod 6y ago
It is two factor still. For example, if you need to give a OTP through sms after puting the credentials. It is possible someone stole the credentials and entered them on another device, but he also has to put the OTP sent through SMS to prove he is also in possesion of the phone number and thus makes the authentication a two factor. If you think both authentications on the same device is one factor, both authentications in the same room is also one factor, going by the same logic - an attacker will have you and everything needed to force his way into your bank account together, then he only needs a big baseball bat to do the job.