However, it's not quite as good as a hardware key, because it's still vulnerable to the third method the article lists: "Calling the target, pretending to be part of the company, and telling the target they need to send an MFA request as part of a company process."
I generally consider TOTP "good enough" for a lot of applications, whereas prompts and SMS are not "good enough."
Few months ago I couldn’t log into the vpn. Posted to the slack channel and got a slack asking my phone number. Ok so I know this guy is really my it and I’m asking for help. Then he sends me a freaking Duo notification! I say “I’m not supposed to click this” and he goes “well yeah but I’m IT”
It’s all very stupid.
I would say the TOTP MFA is easier because you do not have to deal with re inputting the code (which expires) but also then you need another app installed.
I agree those are great
If the site or app poses no choice, just say that you want to use their "Proprietary Authenticator" and you just continue with your own password manager.
It works for me with 1password. As a sanity check too see if it works; you always have to use a first OTP to activate the multifactor authentication.
OTP lets you use your own app.
Notification-based OTP requires a proprietary app.