blog! “Should you enable TOTP *only* authentication?”
Here's a "fun" thought experiment. Imagine a website which let you sign in using only your username and TOTP code. No passwords. No magic links emailed to you. No FIDO tokens. No codes via SMS. Just a TOTP generated and displayed on your device. Is that useful? Sensible? Practical? It's certainly technical…
Read more: https://shkspr.mobi/blog/2024/10/should-you-enable-totp-only-authentication/
⸻
#2fa #CyberSecurity #MFA #totp
@Edent
It sounds way better than the ones that let random crooks spam your inbox with authentication emails in the hopes you'll click at least one of the links.