4 ms·
The team from 1password did a nice writeup, when they introduced storing TOTP in their password manager. Gist is: Most people treat TOTP as a second, time base
by klaustopher 4y ago
The team from 1password did a nice writeup, when they introduced storing TOTP in their password manager.
Gist is: Most people treat TOTP as a second, time based password (multi step authentication) instead of a second factor. If you truly want 2nd factor, you should never sync your passwords to the phone you are using as 2FA, and never use your passwords on the phone you are using as 2FA.
So it depends on your own security concerns if you want to treat TOTP as a true second factor or as a secondary, time based password only.
https://blog.1password.com/totp-for-1password-users/ https://blog.1password.com/totp-for-1password-users/
- tonyedgecombe 4y agoI've always assumed (possibly incorrectly) that my phone is more secure than my desktop.
- circularfoyers 4y agoThey are significantly more locked down and it's hardware more strictly controlled than most desktop OS's, so I would say that assumption is correct. It is looking as though desktop OS's will catch up in this regard considering the progress that's being made with immutable root filesystems and sandboxing with permission sets for user facing programs.
- mrweasel 4y agoPersonally I feel it’s a bit weird when people keep their TOTP on the phone they use to access the service that requires the token. If the idea was to keep things seperate, then either your phone shouldn’t when the tokens, or it shouldn’t be used to access secure services. Hardware token still feel like the safest option, but I also don’t what 8 different token generator in my pocket.
- Symbiote 4y agoA hardware security key would allow you to have one thing in your pocket, used for many sites.
- teaearlgraycold 4y agoDepends on your phone. But it’s also WAY more likely that your phone gets stolen than your desktop does.
- arubania2 4y ago> and never use your passwords on the phone you are using as 2FA Notably, this also involves not logging into the same email account that you use for signups - it would allow the attacker to bypass the password manager completely by requesting a password reset. I guess you could solve this by having one email address for signups and another to communicate with people, but you would still be giving up email notifications (such as “your order has been shipped”) delivered to your phone.