cm0002@lemmy.world to memes@lemmy.world · 22 hours agoTake your passkey and shove it where the sun don't shinelemmy.worldimagemessage-square96fedilinkarrow-up1397
arrow-up1397imageTake your passkey and shove it where the sun don't shinelemmy.worldcm0002@lemmy.world to memes@lemmy.world · 22 hours agomessage-square96fedilink
minus-squareNatanael@infosec.publinkfedilinkarrow-up2·11 hours agoTOTP codes can be phished, hardware security keys and passkey can’t
minus-squareEngywuck@lemm.eelinkfedilinkarrow-up1·8 hours agoI doubt that anyone that doesn’t use “password” as a password and who knows what 2FA is could be easily subject to phishing.
minus-squareNatanael@infosec.publinkfedilinkarrow-up2·3 hours agoIt literally just takes a slightly different domain name. Lots of infosec pros have been phished when not paying attention
TOTP codes can be phished, hardware security keys and passkey can’t
I doubt that anyone that doesn’t use “password” as a password and who knows what 2FA is could be easily subject to phishing.
It literally just takes a slightly different domain name. Lots of infosec pros have been phished when not paying attention