logoalt Hacker News

goatsilast Wednesday at 3:56 PM1 replyview on HN

TOTP and SMS 2FA prevent credential stuffing attacks, which is very valuable considering how bad people are with password reuse and how many breaches with plaintext or weakly hashed passwords there have been.


Replies

tptaceklast Wednesday at 5:16 PM

Yes, but other authentication factors also prevent credential stuffing, as well as phishing, which is probably the most important problem in authentication.