Most people are more likely to lose authenticator tokens (their phone, their yubikey) than be hacked by a sophisticated attacker
Password manager 2FA and SMS 2FA solves the threat model that most people live in
(Organizational security has a far different threat model)
Hypolite Petovan
•silverwizard likes this.
silverwizard
Hypolite Petovan
•silverwizard likes this.
silverwizard
Hypolite Petovan
•silverwizard likes this.
silverwizard
I am talking about getting locked out because you accidentally lost your auth app
Hypolite Petovan
•silverwizard likes this.
silverwizard
You won't lose your phone number for SMS or password manager
Whereas losing a phone with an TOTP authenticator setup or losing a yubikey is pretty simple
Hypolite Petovan likes this.
Bob Jonkman
•@hypolite
Bob Jonkman
•@hypolite
silverwizard
Hypolite Petovan
•silverwizard
Hypolite Petovan likes this.
silverwizard
like this
Hypolite Petovan and Scifijunkie like this.
β w chance of bears
•silverwizard likes this.
silverwizard
But also - I am *far* more likely to lose a phone than by hit by SIM swapping (to be clear - only because I'm a dumbass)
β w chance of bears
•But using Yubico TOTP also basically primed me for "password manager TOTP is functionally the same as Google TOTP but with the convenience of device portability"
silverwizard likes this.
silverwizard
And the answer to that is "it's complicated" - but yeah - in a perfect world we'd all have two security keys, and one is kept in a secure location and one is kept in a wallet/keychain - but that's not feasible (says the man with that)
Hypolite Petovan
•silverwizard likes this.