MFA

alyth@lemmy.world to Mildly Infuriating@lemmy.world – 906 points –
134

You are viewing a single comment

App-based TOTP are not phishing resistant and do not require any level of proximity to the login session. The future is more likely passkeys that use device TPMs.

Simple challenge number handles that, for example Azure AD MFA forces that today

Those are better, but are also not phishing resistant.