4 ms·
SMS OTPs are a vulnerability in the modern age - sim swapping is rife and like you say, it's a usability problem. As others have mentioned, something like 1Pas
by cr3ative 5y ago
SMS OTPs are a vulnerability in the modern age - sim swapping is rife and like you say, it's a usability problem.
As others have mentioned, something like 1Password for TOTP is perfect - multi-device and not tied to any specific device.
- Nextgrid 5y agoThis does somewhat defeat the purpose of 2FA though as both factors are stored in the same place. The purpose of 2FA is to get "something you know" (a password) as well as something you have (your phone or hardware 2FA device). Storing the 2FA secret in a recoverable format and sharing it between devices significantly weakens this security.
- patrakov 5y agoA password should not be "something you know" anyway. If you use a password manager (and you should, because there is no way to store 200+ passwords in your head), then it is "something you have" in your password manager, ideally protected with a single master password that you do know.