I just got the email from haveibeenpwned. F Trello.

  • JustUseMintEnglish
    arrow-up
    1
    arrow-down
    0
    ·
    9 months ago
    link
    fedilink

    Physical token over TOTP authenticator?

    • brianEnglish
      arrow-up
      2
      arrow-down
      0
      ·
      9 months ago
      link
      fedilink

      all the root secrets are available in plain text the generator app at some point, they have to be. moving that to a single purpose device greatly reduces the risk of vulnerabilities in your phone leading to exfiltration via internet connection

    • KayelEnglish
      arrow-up
      2
      arrow-down
      1
      ·
      9 months ago
      link
      fedilink

      I cannot think of a use-case outside of statecraft. Maybe companies engaged, or being engaged, in corporate espionage.