6 ms·
I fell in love with 1Password (and immediately switched from LastPass) once I discovered it can parse and save the Authenticator qr code and auto-paste it at ev
by gnrlst 6y ago
I fell in love with 1Password (and immediately switched from LastPass) once I discovered it can parse and save the Authenticator qr code and auto-paste it at every 2FA step.
- barbazoo 6y agoWhat?!? I have to try that. I hope I can get my codes out of Authy somehow.
- Freaken 6y agoReally? I completely missed that feature.... thanks for the tip!
- gnrlst 6y agoNo problem! When you go on a website that supports 2FA, it usually shows you a QR code to scan in order to setup a 2FA token. Just open 1Password to your current login and click on the tiny little QR code button. 1P detects it and adds it to that login. Blew my mind as well.
- bdcravens 6y agoAll that's in the QR code is a shared secret string, passed into the TOTP algorithm. https://en.wikipedia.org/wiki/Time-based_One-Time_Password https://en.wikipedia.org/wiki/Time-based_One-Time_Password
- gnrlst 6y agoYeah the QR code is not the special part. IT's the UX: 1 click and 1Password reads the QR code and adds a live authenticator code alongside your saved password, and auto-copies it to clipboard on mobile (and auto-pastes it in the 2FA field on desktop). So its like having a password manager and 2FA authenticator app rolled in one. I know it's sorta missing the point, but it's encouraging me to enable 2FA everywhere, as the hassle is now gone. (and most important sites detect when a sign on is unusual anyways).
- bdcravens 6y agoDoesn't this eliminate the advantage of 2FA?
- gnrlst 6y agoYes, in a way. But I find it so incredibly convenient it's actually encouraging me to enable 2FA on all websites that support it (and 1Password lets you know if the website does).
- hosh 6y agoI use it in this way too, but I had been wondering about that as well. Taking a stab at reasoning through this: My understanding is that having a second device means that if the password was stolen, someone still needs another secret to log in successfully. In this case, if a password was stolen from the site itself, the 2fa code generator is not. However, if the 1pass master key was stolen, then both the password and any 2fa code gets stolen as well. That puts the main vulnerability on the master key one uses for 1pass. (So looking at it that way, one should never use the master key as a password for anything else). It does lose the advantage of having a second authentication device, though maybe not necessarily losing the protection of a second factor. Is there something I overlooked in this? I’m no security engineer so I am not used to thinking in this way, other than maybe when I play Go.
- tialaramex 6y ago> My understanding is that having a second device means that if the password was stolen, someone still needs another secret to log in successfully. Stolen from where ? The vast majority of attacks which impact real people on today's web involve the data being stolen from servers in bulk. You should assume bad guys will steal all the available credentials. Is it possible they're too dumb to also dump the table labelled "TOTP Seeds" when they get the "Hashed passwords" table from your favourite web site? Yes, but you can't rely on attackers being incredibly dumb even though many of them are. A password manager makes TOTP moot for these scenarios as I outlined in a separate message in this thread. TOTP doesn't hurt, but if you have to pick between spending ten minutes today adding TOTP codes to accounts in your password manager or going through changing the password from "Liverpool2005" to an actual randomly generated password on a few sites you imported but didn't give fresh passwords, the latter will make much more practical difference.