4 ms·
>It will likely become more popular to require 2FA for password users in the meantime, as it should. A lot of folks/services/engineers mistakenly think that la
by jesseendahl 2y ago
>It will likely become more popular to require 2FA for password users in the meantime, as it should.
A lot of folks/services/engineers mistakenly think that layering 2FA on top of passwords will help defend against phishing attacks.
But attackers have been phishing 2FA codes since at least 2012 and it's gone from an advanced attack to bog-standard. The only way to defend against phishing attacks in 2024 is to use phishing-resistant credentials like passkeys.