Live data from Hacker News

Emailing a one-time code is worse than passwords

blog.danielh.cc

1–10 of 816 posts

Re: Emailing a one-time code is worse than passwords

#8
post #2

Whole heartedly agree. It's not more secure if you only use the second factor of two factor auth.

Codes that are provided on demand by a service will always be far less secure than proper TOTP. Because in the case of proper TOTP, no secret ever leaves the service after initial configuration, but in the case of discount 2FA through email or especially SMS, a fresh secret has to be delivered to me each time, where it can easily be intercepted by all manner of attacks.

Re: Emailing a one-time code is worse than passwords

#9
post #4
post #3

I thought this was going to be about Passkeys. Maybe if the FIDO Alliance can stop being obstinant and allow real backups, I'd be all in on them.

Even with backups, the attestation issue makes them awful.

I'm not familiar with this issue and a quick search didn't turn up anything obvious. Would you mind elaborating?
Post reply on HN