Elektrine lite

← Feed

@rmondello@hachyderm.io

Post #2359377

2026-05-10 19:07 UTC

RE: https://tacobelllabs.net/@ultranurd/116545694379699205 A TOTP provides very little value on top of a passkeys if it’s saved in the same place, with the same access control as your passkey. So in practice, no, you don’t need one. Importantly, note that a TOTP is just as easily phished as a password or an SMS one-time verification code. Now, if your TOTP is stored and accessed separately, it may provide some value, but at that point, your threat model should be pretty advanced and off the beaten path for the risk you’re introducing of locking yourself out of an account.

Replies (3)

  • @rmondello@hachyderm.io Unpopular opinion: A TOTP provides very little value on top of a randomly generated password stored in a password manager. In the meanwhile, if you have 2FA on Amazon, they ask for TOTP/SMS after the passkey.

    Open ##2595473

  • @jsmall@infosec.exchange 2026-05-10 20:32

    @rmondello@hachyderm.io while I agree, in the microsoft world entra wont let you setup a passkey unless you have either Ms authenticator push or totp setup first. I have no idea why.

    Open ##2595475

  • @ridogi@mastodon.social 2026-05-12 02:56

    @rmondello@hachyderm.io @ultranurd@tacobelllabs.net if you have a passkey, you likely still have a password for that site. Even if you aren’t using the password it exists as an authentication method and the TOTP second factor does provide it more protection. The website could leak passwords in a breach for example. Sometimes you can have a password less account that only uses a passkey but it is rare that it is offered that way so far.

    Open ##2595477