auditgood first issue
Description
TOTP is phishable, so ensure the second factor is U2F. Beware that U2F can't be used from the command-line, so you can't enforce 2FA on users with U2F that use access keys.
TOTP is phishable, so ensure the second factor is U2F. Beware that U2F can't be used from the command-line, so you can't enforce 2FA on users with U2F that use access keys.