• flynnguy@programming.dev
      link
      fedilink
      English
      arrow-up
      4
      ·
      20 hours ago

      Email is considered insecure as a 2nd factor. TOTP stands for Time-based One-Time Password. Usually you store a seed and that combined with the time generates a time based password. If someone intercepts it, it’s only valid for a certain time frame (I think about a minute or so), after which it’s invalid.

      • Mose13@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        5 hours ago

        Yes but email is only a second factor when used in addition to a first factor (e.g. password). If it’s just magic link without password, then email is the only factor