4 ms·
I personally use 1password for authenticator codes - highly recommend if you haven't seen it: https://support.1password.com/one-time-passwords/ https://support.
by colinclerk 5y ago
I personally use 1password for authenticator codes - highly recommend if you haven't seen it:
https://support.1password.com/one-time-passwords/ https://support.1password.com/one-time-passwords/
Edit: Didn't answer the actual question - it's something we can look into. My instinct is that offering this wouldn't drastically change the security model, as long as we can be confident your password actually came from a secure password manager. Since some password managers (like 1password) are very strongly tied to devices, I think your ability to retrieve a password from it is a reasonable proxy for a possession factor.
It's definitely something I'd want to read more literature on before building. That's just my instinct, and I'm half expecting someone on HN to share the attack I'm forgetting :)
- Wowfunhappy 5y agoBut doesn't this completely defeat the purpose of the codes, since they're no longer a second factor? I'd rather just not have the codes, as they're still a significant annoyance with next to zero benefit.
- colinclerk 5y agoThere are still some benefits. Your password can probably be bypassed with a "forgot password" flow while the TOTP code cannot. Aside from that, though, I think it's reasonable to argue that the security of password+code in 1password is equivalent to just password in 1password.
- aetherspawn 5y agoIf someone scrapes your clipboard or records your screen for example, this still adds a second layer of protection.
- Wowfunhappy 5y agoThey can't scrape the clipboard because of autofill, and they can't record the screen because passwords appear as ******.
- ornornor 5y ago> passwords appear as hunter2. You should be careful about copy pasting your password on the internet.
- Wowfunhappy 5y agoHuh? That’s not what I wrote...
- ornornor 5y agoSee http://bash.org/?244321 http://bash.org/?244321
- Wowfunhappy 5y agoThank you. It was a clever reference on your part, I just hadn't seen it before. :)
- ornornor 5y agoHehe you learn something new every day