I just got the email from haveibeenpwned. F Trello.

  • @JustUseMint
    link
    English
    110 months ago

    Physical token over TOTP authenticator?

    • @[email protected]
      link
      fedilink
      English
      210 months ago

      all the root secrets are available in plain text the generator app at some point, they have to be. moving that to a single purpose device greatly reduces the risk of vulnerabilities in your phone leading to exfiltration via internet connection

    • @[email protected]
      link
      fedilink
      English
      110 months ago

      I cannot think of a use-case outside of statecraft. Maybe companies engaged, or being engaged, in corporate espionage.