3 ms·
There's an obvious tradeoff having an authenticator (2FA/OTP) separate from your secure password manager. If you lose the device with credentials, you're screwe
by PennRobotics 5y ago
There's an obvious tradeoff having an authenticator (2FA/OTP) separate from your secure password manager. If you lose the device with credentials, you're screwed. It's really easy to lose access to a device (and usually without advance notice).
Or you can override the 2FA, and then you're back to hoping the verification procedure of overriding 2FA is stronger than a dedicated attacker. A password manager managing 10 OTP accounts means 10 attempts at social engineering to bypass the OTP.
I realize having everything on the password manager goes against the "a thing you know plus a thing you have" security policy, but I imagine you'd have much more grief linking every account to a device (a smartphone, usually) you expect can (more likely: will) fail in the next 0 to 6 years.
On the flip side, if you decide to make the thing you have a biometric feature, there's the downside that this thing can never be changed but could possibly be spoofed. In twenty years, you'll still have the same fingerprints, and you even have the same fingerprints, iris, face, etc. when you're unconscious.
Maybe the best strategy is a hardware key with printed backup code? Then you really need to hide the printout somewhere only you know, where it won't get destroyed, where it can be accessed relatively quickly without a complicated lockout, where it won't get accidentally discovered by the HVAC repairman, and where you won't forget after 0 to 6 years. Solving this location riddle seems the most impossible of all...
- blfr 5y ago> Maybe the best strategy is a hardware key with printed backup code? Or register more than one (preferably three) hardware key. It sidesteps all of these issues. They are very resilient and act as backups.
- PennRobotics 5y agoYou still need to store one backup key somewhere safe, and then it's no longer something you have but something you hope stays where you left it.
- jamesmishra 5y agoBut then where do you put the hardware keys? Presumably you would need to obtain all three keys every time you register a new user account on a website.