5 ms·
Your passwords and two-factor keys should not be accessible through the same service. If 1Password is hacked, both forms of authentication are compromised.
by HappyRobot 9y ago
Your passwords and two-factor keys should not be accessible through the same service. If 1Password is hacked, both forms of authentication are compromised.
- CodeWriter23 9y agoSo, if your phone using any password manager of your choice, Plus Google Authenticator for TOTPs is compromised, same level of risk, right? Because GA has no challenge nor authentication to dump your TOTPs.
- dexterdog 9y agoYes, but if you can put your 2fa manager behind something like samsung knox it gives you some level of separation.
- AdmiralAsshat 9y ago> Because GA has no challenge nor authentication to dump your TOTPs. Define "dump". GA won't challenge you to display the one-time TOTP code, no. It would be incumbent upon you to lock your device. But as far as dumping those codes out into a state such that a malicious actor could then take them and import them onto another device, no, that is not easily doable. As the distant parent noted, Google Authenticator stores the stuff in an encrypted sqlite database that is not extractable without root access. I don't think even run-of-the-mill adb debug commands can get it out.