4 ms·
I would have thought the advice here would be use passkeys everywhere you can and avoid Totp altogether (particularly the sms variant which has real risks today
by beardedwizard 2y ago
I would have thought the advice here would be use passkeys everywhere you can and avoid Totp altogether (particularly the sms variant which has real risks today). When I think big picture mfa exists because passwords are often assumed lost to infostealers, so changing your password seems moot for an adversary who is ready to brute force your mfa.
- ezekg 2y ago> I would have thought the advice here would be use passkeys everywhere you can and avoid Totp altogether (particularly the sms variant which has real risks today). Why would you avoid TOTP altogether? Yes, SMS OTP is insecure because SMS is insecure, but OTP itself is fine, unless I missed something?
- computerfriend 2y agoTOTP is phishable.
- halfcat 2y agoPasskeys address the phishing angle, but as always it’s a trade off. With passkeys if someone gets remote control of your computer they have access to everything you setup a passkey for. Typically people say “well full remote control is far less common than phishing”, and it is, for now, until everyone’s using passkeys and all of the sophisticated phishing attack effort just shifts to passkeys. The obvious weak point here is all of the outsourced IT who aren’t specifically focused on cybersecurity. Every IT company is using multiple tools for central management that either allows remote control or remote execution, or there’s always in-house developers who realistically aren’t doing a security analysis of every third-party library they’re installing.
- beardedwizard 2y agoYou can still require biometric to unlock passkey for each use, so the risk is really about authenticated session theft in that scenario