Quote Originally Posted by Raim View Post
This is why you should use a OTP in the first place too. Makes it nigh impossible to be hacked. Even if you flat out told someone your credentials and current OTP, it would prompt them with a different OTP they don't have access to. And trying to remove OTP is impossible without that one secret key.
OTP works well against weak or leaked passwords. But it does not work very well against keyloggers or faked websites. Because if you enter the OTP into the replaced loging window then the hackers can immediately use it.


Cheers