I am talking about TOTP from authenticator apps. From my understanding, the TOTP is fully determined by the secret key. Then isn’t it effectively the same level of security as simply having two passwords? Is the main advantage that these two are (ideally) stored in two different locations so it’s harder to gain access to both?
Both my password manager and the authenticator app live on my phone, so getting access to my phone already exposes both.
Also I guess entering the TOTP is safer because it does not expose your secret key, making it more resilient to key-loggers and phishing attacks. But then what is the need for the password itself, why not just have the TOTP to log in?
[link] [comments]
SOCIAL SHARE CARD GENERATOR