OTP request
-
hi.
i had a thought in me the other day.
what if in stead of using a regular oll password, users could use OTP methods, like TOTP or yubikey OTP?
and not just for 2FA, but for actual logins.
this, from my understanding, would also decrease the chance of a hacker getting in, as they would need the OTP, and not just 1 20 character password.
of course, this could be fished, but this could easily be stopped via employee education. and well, passwords can be fished anyway.