I don't know who needs to hear this but: Just use TOTP.

Don't send me a text, don't email me. Just. use. TOTP.

If you want to get fancy, do passkeys or Yubikeys or whatever, but TOTP is fine.

Reply to this note

Please Login to reply.

Discussion

I use TOTP all the time.

I don't have a Yubikey, and I don't understand passkeys enough to trust them yet.

Oh, I meant for web devs who implement 2fa, and decide to roll their own email or SMS based thing instead for some reason.