2014-10-13 UTC
# ben_thatmust the reason it works so well as 2 factor auth is that it obscures your password correctness on a brute force. so if you try to brute force password, even if you get it right you have to provide a proper TOTP, so (properly implemented) you don't know if you guessed the password correctly or the TOTP failed