What the title says. Before you had to choose either SMS / call via phone or a very clunky code grid.

@rinze@infosec.pub
creator
link
fedilink
29M

Wealthsimple and Questrade seem to support TOTP but I’m not sure if you can still bypass it with SMS. I don’t think so but I haven’t dug into it.

Questrade allows TOTP, SMS and some other methods, but you can select which ones you want to enable. I have only TOTP and it works as expected.

Thanks, I suspected this (I only see “authenticator app” when I log in on a new device or periodically, but I wasn’t sure.

Related: for finance related services like Questrade, I’ve stored my TOTP keys on a U2F key, Yubico in my case. Besides the hassle of managing physical keys, is there any drawback to this approach? I’m slightly worried I’ll lose all my keys in a house fire or something, but I assume there’s a recovery option.

@rinze@infosec.pub
creator
link
fedilink
19M

That I don’t know. I store the TOTP keys into an app on my phone an into a separated KeePass DB that’s different from my regular one. Two copies of that is good enough to let me sleep at night.

Create a post

What’s going on Canada?



Communities


🍁 Meta

🗺️ Provinces / Territories

🏙️ Cities / Local Communities

🏒 Sports

Hockey

Football (NFL)

  • List of All Teams: unknown

Football (CFL)

  • List of All Teams: unknown

Baseball

Basketball

Soccer


💻 Universities

💵 Finance / Shopping

🗣️ Politics

🍁 Social and Culture

Rules

Reminder that the rules for lemmy.ca also apply here. See the sidebar on the homepage:

https://lemmy.ca


  • 1 user online
  • 164 users / day
  • 286 users / week
  • 574 users / month
  • 1.99K users / 6 months
  • 1 subscriber
  • 5.74K Posts
  • 51.2K Comments
  • Modlog