• TheObviousSolution@lemmy.ca
    link
    fedilink
    arrow-up
    1
    ·
    4 hours ago

    If you can get at a password by hacking a website, I wouldn’t be holding out hope that they couldn’t then steal the TOTP secret.

    • BCsven@lemmy.ca
      link
      fedilink
      arrow-up
      1
      ·
      4 hours ago

      I mean yes everything is hackable. Thankfully the hardware key supports FIDO where there is a public / private pair with private locked on the hardware. Not enough services support this though.

      So threat is being targeted and having somebody steal the hardware key.