3 ms·
> Also it was only a few years ago Sony was caught storing passwords in plaintext so… Unless you trust the service is hashing and salting your password, MFA can
by gregmac 4y ago
> Also it was only a few years ago Sony was caught storing passwords in plaintext so… Unless you trust the service is hashing and salting your password, MFA can be a good idea.
Though that site is likely also storing the TOTP shared secret in plaintext, beside the password, making it pretty much pointless. If the site itself is compromised, it's hard to come back from that.
Pretty much the best thing you can do is never re-use passwords across sites.