top | item 44821365

(no title)

antaviana | 6 months ago

If we are talking about real time phishing then sending a code to the email is as secure as a 2FA authentication with password and Google Authenticator code.

discuss

order

Hackbraten|6 months ago

My password manager will protect me from entering my password into a website on the wrong domain. It won’t protect me in the passwordless case where the code is sent via email.

SethMurphy|6 months ago

Can you explain this more, I don't understand Google authenticator completely? Could a bad actor spoof a 2FA as they can with an email, and capture your input?

delusional|6 months ago

The attacker would just ask you for the TOTP code and forward that to Google.