zlacker

[parent] [thread] 0 comments
1. lxgr+(OP)[view] [source] 2024-12-27 14:33:21
To me, they're an annoying half-measure: Not phishing/MITM resistant, yet annoying to use in practice.

I'll still take them over SMS-OTP any day, but admittedly even that at least offers some technical benefits over TOTP, e.g. in that the relying party can tell me what I am consenting to in the message ("by entering this code, you approve a payment of $1000 to evilshop.com").

[go to top]