Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because those OTPs can be intercepted by any MITM unless you are using on-device 2FA generated by an app.


> intercepted by any MITM

Most things are... even SSH is Trust-on-First-Use. You can really only verify out of band. OTP is quite a bit better than CC or bank account numbers... assuming the OTP is only restricting use (and not giving access to view or modify other account information, etc)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: