Quote Originally Posted by Ash_ View Post
One time password app on IOS/Android or a security token would also keep your account protected. It honestly needs to be mandatory.
Not from the phishing scam the link you get sent to looks like the login page,you enter all your login info, including the OTP. As it is logging the phisher in at the same time and you are providing them with the number they get in.