4 ms·
1Password captures and stores TOTPs, even copies the current OTP into your clipboard momentarily when you log in to a site. You don’t have to use their online s
by CodeWriter23 9y ago
1Password captures and stores TOTPs, even copies the current OTP into your clipboard momentarily when you log in to a site. You don’t have to use their online service; you can keep the password vault in a file. You can sync your devices over LAN and WiFi.
- dexterdog 9y agoThus defeating the purpose of 2fa
- gonvaled 9y agoCan you ellaborate?
- HappyRobot 9y agoYour passwords and two-factor keys should not be accessible through the same service. If 1Password is hacked, both forms of authentication are compromised.
- CodeWriter23 9y agoSo, if your phone using any password manager of your choice, Plus Google Authenticator for TOTPs is compromised, same level of risk, right? Because GA has no challenge nor authentication to dump your TOTPs.
- dexterdog 9y agoYes, but if you can put your 2fa manager behind something like samsung knox it gives you some level of separation.
- AdmiralAsshat 9y ago> Because GA has no challenge nor authentication to dump your TOTPs. Define "dump". GA won't challenge you to display the one-time TOTP code, no. It would be incumbent upon you to lock your device. But as far as dumping those codes out into a state such that a malicious actor could then take them and import them onto another device, no, that is not easily doable. As the distant parent noted, Google Authenticator stores the stuff in an encrypted sqlite database that is not extractable without root access. I don't think even run-of-the-mill adb debug commands can get it out.