4 ms·
TOTP is phishable. Don't use that.
by drivebycomment 4y ago
TOTP is phishable. Don't use that.
- pdonis 4y agoHow is TOTP phishable?
- Macha 4y agoThe browser won't help you avoid putting it in the login form at google.com.fakehackersite.com which can then just relay that to real google. I think this is still an improvement over SMS, and personally is something that risk wise I'm happier with than the idea that if I lose a yubikey or it breaks down it's game over.
- xp84 4y agoAh, i see. definitely a concern for if i were administering an org. I still like TOTP vastly better than the only alternative with wide reach, the dreaded and stupid "code sent via SMS" but I hear you on the risk with unsophisticated users who click things. Maybe this WebAuthn thing will catch on and help? fingers crossed.
- drivebycomment 4y ago> I hear you on the risk with unsophisticated users who click things. The evidence says this attitude of "it's other people who get phished and not me" is pure arrogance. Practically all sophisticated security professionals can be phished with sufficiently sophisticated attacks, if the underlying system is using a phishable credential.