4 ms·
Incidentally, many services are now requiring a cellphone to send some one time password via SMS. Your phone number is something that you actually pay for and c
by aduitsis 6y ago
Incidentally, many services are now requiring a cellphone to send some one time password via SMS. Your phone number is something that you actually pay for and can transfer between carriers as you see fit. So in that sense, it's much more predictably controllable and, more importantly, under the legal jurisdiction of your own country.
- quesera 6y agoOTP via SMS is not safe enough for any person/organization who might be targetted by a motivated attacker. TOTP gives you better control over risk (good hygiene is achievable), whereas depending on SMS is outsourcing your risk management to low-paid carrier employees.
- ClumsyPilot 6y agoHow does TOTP solve the reset email problem, what do you do if your phone is destroyed/lost/stolen and you don't have TOTP app any more?
- busterarm 6y agoThat's why you were supposed to backup recovery keys at the beginning and store them somewhere safe. Like on a piece of paper in a safe. An encrypted database works too.
- srockets 6y agoI don't think good hygiene is achievable in practice – some phishing websites are extremely deceiving. I wouldn't bet on myself, a technically capable professional, being able to distinguish some of them, especially in a planned attack: for example when trying to login to a dashboard after being woken up by a page middle of the night, I might not notice a homograph attack. TOTP is better than SMS, both are better than second factor, but it's a great idea to mandate U2F/Webauthn if you can.