4 ms·
Well the seed is protected by the PK (the 1P salt certificate) and the master vault password, so even if the account password is leaked or realistically keylogg
by aetherspawn 5y ago
Well the seed is protected by the PK (the 1P salt certificate) and the master vault password, so even if the account password is leaked or realistically keylogged, you still get nearly all of the protection from 2FA in that case since only your devices have the 1P salt required to decrypt the 2FA seed. I don’t think that the ‘common password’ attack that 2FA would typically protect from even applies if you are using a password manager where each account is a random password. In this case you’re only protecting yourself from keyloggers or such.
My 2c.