Reply to post: 2FA has been broken for a while

LastPass now supports 2FA auth, completely undermines 2FA auth

Kevin McMurtrie Silver badge

2FA has been broken for a while

You log in from your phone and a verification token is pushed to your phone. That's not 2FA anymore. It just means that the malware needs to be put on your phone rather than your desktop computer.

Token generator key fobs are a bit better because it must be physically stolen and used before the owner deactivates it.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon