3 ms·
Skip OTP, give us FIDO2/Webauthn for everything. OTP is vulnerable to phishing. I was pleasantly surprised when both Bank of America and Vanguard leapfrogged f
by mk12 5y ago
Skip OTP, give us FIDO2/Webauthn for everything. OTP is vulnerable to phishing.
I was pleasantly surprised when both Bank of America and Vanguard leapfrogged from SMS MFA to security keys. I bought 3 and started using them for every service that allows me to. Even better are services (e.g. Bitwarden, GitHub) that don't restrict to security keys, then MacBook Pro and iPhone Touch ID can be registered as well.