3 ms·
Or email if email is the username
by ab_testing 5y ago
Or email if email is the username
- ezekg 5y agoIf you’re doing an emailed TOTP, you might as well do a “magic link” at that point. I dislike both (prefer a secure TOTP app), but here one offers a better UX over the other.
- sp332 5y agoI'm not sure about the email thing, I've just never used TOTP by email. Anyway I don't see anything glaring. The TOTP code has enough entropy that it won't get cracked in any reasonable amount of time. If you rate-limit login attempts, that would be better, but either way I think it's infeasible to crack. And it's a lot better than letting users use short or common passwords that are on some list already!