4 ms·
Being tied to a device, it defeats the most serious threats of phishing and weak passwords, for which attacks can be mounted on a global scale. 2FA via SMS is
by bhk 3y ago
Being tied to a device, it defeats the most serious threats of phishing and weak passwords, for which attacks can be mounted on a global scale.
2FA via SMS is still vulnerable. 2FA with an app like Google Authenticator or VIPAccess is more secure because it is tied to a device.
- ilyt 3y agoThe devices are far from being security bastion.
- jjav 3y ago> more secure because it is tied to a device Tied to a phone (as opposed to some security-specific device like a Yubikey) is a terrible idea. It ties your authentication to something that is often lost or damages, but more importantly, something that is controlled by a third party (apple or google) and requires an expensive monthly subscription to yet another third party (your cellphone company). TOTP is not tied to a device which is why it's a beautiful solution. You can store it where you wish under the controls you wish and back it up as you wish. You are fully in control, dependent on nobody.