3 ms·
Doesn't it kinda defeat the point of storing TOTP codes in your password manager?
by mattrick 6y ago
Doesn't it kinda defeat the point of storing TOTP codes in your password manager?
- swirepe 6y agoYou wouldn't need to store the codes, but you would need to store the key that makes the codes.
- m-p-3 6y agoIf it's secured by TOTP and a unique and secure password, it's not the weakest link.
- chromakode 6y agoThis reduces the attack scope from two devices to one. If your computer or web browser is compromised then both your TOTP secrets and password secrets are in one basket. Storing TOTP on a separate device can make it significantly harder to compromise your accounts.
- literallycancer 6y agoHe might be using two different password manager accounts, one for passwords and one TOTP? Although it doesn't help much if he logs in from the same machine anyway.
- cdurth 6y agoI would say not when you can secure bitwarden with a hardware key 2FA.
- Denvercoder9 6y agoPartially, but it still offers protection against e.g. replay attacks and e-mail hacks.