2026-03-14 13:03 UTC
It's not actually reduced to one factor, just a single point of failure. If their password manager gets taken it's a problem, however the generated TOTP is worthless in 1 min. So this will protect the login from cases where the password is known like a compromised website or a reused password.
Replies (2)
-
@TheObviousSolution@lemmy.ca 2026-03-14 15:52
If the site is compromised, then the hackers could have stolen the TOTP secrets as well as the passwords. How do you think the site verifies TOTP codes? If you reuse passwords while using a password manager, you are asking for it, though.
-
@Coleslaw4145@lemmy.world 2026-03-14 13:37
But if a password manager is compromised then doesn't the attacker also get the TOTP key which is what generates the codes in the first place? It wouldn't matter if it expires in one minute because they'll have the token to generate the next code, as well as now knowing the password.