3 ms·
I keep TOTP separate on my phone. Password database will be decrypted in memory after it's unlocked and can be dumped with sufficient privileges. You could arg
by m3nu 5y ago
I keep TOTP separate on my phone. Password database will be decrypted in memory after it's unlocked and can be dumped with sufficient privileges.
You could argue that an attacker with access to copy the password DB can intercept OTP as they are entered, but that seems much more work than running off with everything at once.