Why does nobody talk about 2FA codes getting stolen in real time?
I set up an authenticator app 8 months ago and felt pretty safe until a guy on a forum showed me how a fake login page grabs your code the second you type it. He walked me through it with a demo site and I watched my own 6 digit code get used to log in before the 30 second timer even ran out. So what is the actual fix here, do I just stop using codes and go hardware key only?
That part about watching your own code get used "before the 30 second timer even ran out" hit me hard because the same thing happened to me last year. Somebody sent me a link to a fake crypto exchange login and I typed my code in without thinking twice. They had a bot sitting there waiting and it punched the code into the real site in like 5 seconds. The timer does nothing to protect you when the thief is copying it live in the same 30 second window. That was the day I finally got it through my head that any code you can type, somebody else can grab and use. I still keep the app as a backup but the important stuff all runs on hardware keys now.