4 ms·
If your password store is owned then the attacker has both your credentials and the second factor. So in that way, the password manager has sacrificed a securit
by CodeWriter23 4y ago
If your password store is owned then the attacker has both your credentials and the second factor. So in that way, the password manager has sacrificed a security fail-safe.
- sgjohnson 4y agoIf your password store is owned, you’re fucked. Period. 2FA will offer little failsafe in such a scenario.
- nicoburns 4y agoWhy so? If you don't have second factors in your PW store, then any service which actually implements MFA properly shouldn't let anyone have access to anything.
- jjav 4y agoNot quite, that's why 2FA is supposed to be a second factor, not just extra data in the same place. If your second factor is on separate hardware then even total compromise of the first piece of hardware (the laptop containing the password database) is not sufficient. The separate hardware could be many things. One is something like yubikey etc. Or a separate computer with the TOTP secrets, etc.
- CodeWriter23 4y ago> If your password store is owned, you’re fucked. Period. Factually incorrect. In that scenario, REAL 2FA (the kind not stored in the password store) is the only thing keeping bad guys out until you change passwords.