4 ms·
It's a misfeature using e-mail for 2FA login codes. TOTP is far more reliable. Any service doing e-mail only 2FA should be called out and questioned. Never assu
by favourable 4y ago
It's a misfeature using e-mail for 2FA login codes. TOTP is far more reliable. Any service doing e-mail only 2FA should be called out and questioned. Never assume a user has access to their email at all times.
- usr1106 4y agoRight, I must admit I had never heard of email being used for 2FA codes. Is that some kind of standardized protocol or something completely homegrown? In the far past (and still today with 2 banks) I use hardware/smartcard based solutions. But everything vaguely IT world seems to use TOTP. They typically advertise it as Google Autenticator, but I use different FOSS implementations on both PC and phone and they have worked 100% smoothly.
- gruez 4y ago> Right, I must admit I had never heard of email being used for 2FA codes. Is that some kind of standardized protocol or something completely homegrown? If you don't have 2fa explicitly set up and browse with VPN enabled, you'll frequently get sites that want you to authenticate via email. Amazon does this, for instance.