logoalt Hacker News

8n4vidtmkvmktoday at 1:31 AM1 replyview on HN

I thought the same for a long time but now i don't know. If your computer is compromised, they can exfiltrate your password, but with a hardware key they can't, so i think that's legitimately more secure than password+otp. It still needs a pin though to protect against device theft. I bring this up because there's been a ton of compromised developer packages recently and windows itself is being attacked so even if you're pretty good about protecting yourself, you still might get screwed.


Replies

nvme0n1p1today at 1:44 AM

If your computer is compromised, the attacker can just as easily read your email.

OTP can be used with a password.