3 ms·
True, but there are many other ways people can lose control of their password other than the site being owned and TOTP helps in most of them, right? PW phished,
by markc 9y ago
True, but there are many other ways people can lose control of their password other than the site being owned and TOTP helps in most of them, right? PW phished, shoulder surfed, socially engineered, etc.. I agree that separate devices is better, but given the choice of no 2FA and storing both secrets in 1PW, it still seems to me like you're better off with the latter. Happy to be corrected if I'm wrong on that.
- tptacek 9y agoIf there is a security benefit to enabling TOTP and then storing the secret in 1Password alongside your 1Password-generated password for that site, it is extremely marginal. I don't think TOTP is dumb; I think you should use it, but only let the keys touch your phone, never your computer.
- OrwellianChild 9y agoCan I ask for clarification? If I'm managing passwords with 1Password on both my Android phone and my Windows desktop, how can I effectively use my TOTPs as a second factor? Is it enough to run the TOTPs through the Google Authenticator on my phone (alongside 1Password on the same device)? I'm unclear on what kind of separation is "useful" separation and looking for the "right" way to set this up.