Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you use a password manager that's two factor, then you are still at two factors. e.g. vault-based or hardware key based


I justify the second factor as having the 128-bit security key for the vault.

It's not that easy to install a 1Password vault onto a new device, so I'm okay with the 2FA codes getting stored in the same place as the passwords and sync between.

The realistic scenerio for my passwords leaking is target database exploitation or MITM attacks and not vault exploitation. The 2FA is still a rolling phrase that makes any capture of my password useless after about 1 minute, and not only that but I actually even get email notifications ('xx logged in from a new device') if someone uses my password but can't get past my 2FA. It feels very secure and I reject the dogma that 2FA means 2 separate physical devices.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: