Post #2359377
2026-05-10 19:07 UTC
Replies (3)
-
@BucciaBuccia@mastodon.social 2026-05-10 19:22
@rmondello@hachyderm.io Unpopular opinion: A TOTP provides very little value on top of a randomly generated password stored in a password manager. In the meanwhile, if you have 2FA on Amazon, they ask for TOTP/SMS after the passkey.
-
@jsmall@infosec.exchange 2026-05-10 20:32
@rmondello@hachyderm.io while I agree, in the microsoft world entra wont let you setup a passkey unless you have either Ms authenticator push or totp setup first. I have no idea why.
-
@ridogi@mastodon.social 2026-05-12 02:56
@rmondello@hachyderm.io @ultranurd@tacobelllabs.net if you have a passkey, you likely still have a password for that site. Even if you aren’t using the password it exists as an authentication method and the TOTP second factor does provide it more protection. The website could leak passwords in a breach for example. Sometimes you can have a password less account that only uses a passkey but it is rare that it is offered that way so far.