3 ms·
In a multi-factor scheme, I would agree with you. I use FIDO/U2F myself...as a secondary factor. There are active attacks that attempt to exploit human lack of
by bedast 4y ago
In a multi-factor scheme, I would agree with you. I use FIDO/U2F myself...as a secondary factor.
There are active attacks that attempt to exploit human lack of vigilance in an authentication approval flow. With a password as a first factor, it reduces the chances that these attempts make it to the user.
You and I are probably fine in terms of vigilance. If I see an auth request, say, from my Okta app, that I did not initiate, I know it's something I need to investigate and will not automatically approve it. But consider the typical user...