Emailing a one-time code is worse than passwords
blog.danielh.cc
Emailing a one-time code is worse than passwords
1–10 of 816 posts
Re: Emailing a one-time code is worse than passwords
#2Whole heartedly agree. It's not more secure if you only use the second factor of two factor auth.
Re: Emailing a one-time code is worse than passwords
#3I thought this was going to be about Passkeys. Maybe if the FIDO Alliance can stop being obstinant and allow real backups, I'd be all in on them.
Re: Emailing a one-time code is worse than passwords
#4I thought this was going to be about Passkeys. Maybe if the FIDO Alliance can stop being obstinant and allow real backups, I'd be all in on them.
Even with backups, the attestation issue makes them awful.
Re: Emailing a one-time code is worse than passwords
#5They aren’t ideal but are they actually worse than passwords? I’d bet that on net, more compromises happen with previously-leaked passwords
Re: Emailing a one-time code is worse than passwords
#6Lot's of services realized that users would use the reset password form for login.
Re: Emailing a one-time code is worse than passwords
#7I'm having difficulty understanding what it means for an attacker to "send your email to a legitimate service"...
Re: Emailing a one-time code is worse than passwords
#8Whole heartedly agree. It's not more secure if you only use the second factor of two factor auth.
Codes that are provided on demand by a service will always be far less secure than proper TOTP. Because in the case of proper TOTP, no secret ever leaves the service after initial configuration, but in the case of discount 2FA through email or especially SMS, a fresh secret has to be delivered to me each time, where it can easily be intercepted by all manner of attacks.
Re: Emailing a one-time code is worse than passwords
#9I thought this was going to be about Passkeys. Maybe if the FIDO Alliance can stop being obstinant and allow real backups, I'd be all in on them.
Even with backups, the attestation issue makes them awful.
I'm not familiar with this issue and a quick search didn't turn up anything obvious. Would you mind elaborating?
Re: Emailing a one-time code is worse than passwords
#10I'm having difficulty understanding what it means for an attacker to "send your email to a legitimate service"...
[deleted]