Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I was going to disagree with you (and I sort of do about password managers and storing 2FA in them

Note I'm quoting HIBP's advice from the email they've sent me! I'm absolutely not recommending to store one's 2FA secrets in the same place as the password!

Even if one uses 2FA for the password manager, it stops proving "something you have" in addition to something you know and you're one unlock away from malware vacuuming it all up. The point of 2FA is to be on a separate device you need to have on hand

Of course, the same logic goes for a password manager in the first place, but password reuse is a big enough problem that (for most people's threat model) it seems to be a net positive. 2FA tokens don't have that reuse issue



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: