Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
staticassertion
5y ago
0 comments
Save
Share
TOTP is an improvement over SMS in that identity is not tied to a phone number, which has been proven over and over again to be a terrible indicator of identity.
0 comments
2 comments · 1 top-level
top
newest
oldest
UncleMeat
5y ago
· 1 in thread
That isn't a meaningful distinction. Both cases involve you typing in a number into a web form.
staticassertion
OP
5y ago
It was a meaningful distinction to the OP...
While TOTP contains a bypass (phishing) SMS contains an additional
vulnerability
.
j
/
k
navigate · click thread line to collapse