I just got the email from haveibeenpwned. F Trello.

  • JustUseMintdeleted by creator
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 年前

    Physical token over TOTP authenticator?

    • brian@programming.dev
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 年前

      all the root secrets are available in plain text the generator app at some point, they have to be. moving that to a single purpose device greatly reduces the risk of vulnerabilities in your phone leading to exfiltration via internet connection

    • Kayel@aussie.zone
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      2 年前

      I cannot think of a use-case outside of statecraft. Maybe companies engaged, or being engaged, in corporate espionage.