logoalt Hacker News

Ferret7446yesterday at 4:37 PM1 replyview on HN

Exactly, which is why TOTP is "weak". "Real" 2FA like FIDO on a security key makes it much harder.


Replies

ACCount37yesterday at 7:20 PM

TOTP is the "good enough" 2FA.

If I managed to intercept a login, a password and a TOTP key from a login session, I can't use them to log in. Simply because TOTP expires too quickly.

That's the attack surface TOTP covers - it makes stealing credentials slightly less trivial by making one of the credentials ephemeral.

show 1 reply