alyth@lemmy.world to Mildly Infuriating@lemmy.worldEnglish · 2 years agoMFAlemmy.worldimagemessage-square84fedilinkarrow-up1809arrow-down137
arrow-up1772arrow-down1imageMFAlemmy.worldalyth@lemmy.world to Mildly Infuriating@lemmy.worldEnglish · 2 years agomessage-square84fedilink
minus-squareMSids@lemmy.worldlinkfedilinkEnglisharrow-up3arrow-down2·2 years agoApp-based TOTP are not phishing resistant and do not require any level of proximity to the login session. The future is more likely passkeys that use device TPMs.
minus-squareHotzilla@sopuli.xyzlinkfedilinkEnglisharrow-up1·2 years agoSimple challenge number handles that, for example Azure AD MFA forces that today
minus-squareMSids@lemmy.worldlinkfedilinkEnglisharrow-up2·2 years agoThose are better, but are also not phishing resistant.
App-based TOTP are not phishing resistant and do not require any level of proximity to the login session. The future is more likely passkeys that use device TPMs.
Simple challenge number handles that, for example Azure AD MFA forces that today
Those are better, but are also not phishing resistant.