2 ms·
For the vast majority of services, dump the passwords requirement then. Physically stealing a token from me is a much riskier, less scalable attack than slingi
by yodelshady 3y ago
For the vast majority of services, dump the passwords requirement then.
Physically stealing a token from me is a much riskier, less scalable attack than slinging hashes from someone's hobby site into GPUs.
- tialaramex 3y agoAlso outside of Hollywood movies there's not a great intersection between people who are great at this sort of hands on crime (e.g. robbery, pick pocketing) and the high level strategy needed to want a specific person's MFA token. Tom Cruise would play a character who does that (and rides a motorcycle, obviously) but in the real world it's not a thing. Unlike car keys the tokens don't even know what they're for. You can walk around a car park with keys and match the car, these days it'll even remotely blip the lights - but if you have some random guy's Yubico Security Key, you don't even know if he uses Facebook, Google, PyPI, or what, let alone what the account's username/ email might be. Good luck.