• 2 Posts
  • 151 Comments
Joined 2 years ago
cake
Cake day: February 19th, 2024

help-circle
















  • That doesn’t sound like a TOTP vs passkey situation though. It sounds like the program just releases the passkey when you give it the fingerprint. There wouldn’t be anything stopping the program from generating a OTP and passing that along when you identify with the fingerprint.

    I think a big issue is how difficult it can seem to be to get easy access to TOTP codes, like in your example digging up your phone. But that’s more of a browser/operating system failure for not implementing a way to generate those codes like they can already store usernames and passwords.




  • Kinda yes, but really no. If they assume there is always a comma, but if you add it after you’ve generated whatever password you’ve chosen you’re still making it harder for them. You haven’t compromised on the length, and now they need to figure out where in the rest of your random password the comma goes.