←back to thread

656 points EthanHeilman | 1 comments | | HN request time: 0.362s | source
Show context
unethical_ban ◴[] No.30106682[source]
TOTP is not going anywhere for much of the Internet. Hold on while I get a Yuibikey to my dad who thinks "folders can't be in other folders" because that's not how they work in real life.

TOTP is a great security enhancement, and while phishable, considerably raises the bar for an attacker.

The fact that TOTP is mentioned as a bad practice in this document is an indicator that this should not be considered a general best practices guide. It is a valid best practice guide for a particular use case and particular user base.

replies(3): >>30106810 #>>30106859 #>>30110488 #
1. adgjlsfhk1 ◴[] No.30106810[source]
the advantage of fido2/webauthn is actually biggest for non techies. tech people are the ones who won't fall for take bad phishing attempts. stopping malicious logins from fake sites is a massive win.