5 ms·
Just keep TOTP in your password manager at this point. Whatever security is lost by it not being a "true second factor" is made up for by not having to recover
by Lucent 4y ago
Just keep TOTP in your password manager at this point. Whatever security is lost by it not being a "true second factor" is made up for by not having to recover or restore backups due to a lost or stolen phone.
- Semaphor 4y agoRestoring backups is extremely easy, though.
- arepublicadoceu 4y agoI would argue that the most important account to have TOTP enabled IS your password manager. So, if you already have a TOTP app to generate codes for your Password Manager why not consolidate it? Besides, if you dont have a physical and digital backup of your TOTP seeds you really like to live dangerously.
- howinteresting 4y ago2fa for your password manager is good, but that doesn't have to be TOTP. That can just as well be something like the 1password secret key (something you have).
- plumeria 4y agoI think that's the idea behind using a key file and a password in KeepassXC.
- unethical_ban 4y agoThe one place I intentionally don't have TOTP is my password manager. there is a base case somewhere in a backup strategy where TOTP is not feasible. The base case for me is "Keepass file backed up to multiple locations and my master key written down in an envelope in my house in case I hit my head". Why would I lock my passwords away behind a TOTP that can get lost? My TOTP in Authy is protected by a long random key. Where do I store the key? In my password manager. You can't use a password manager and TOTP to back each other up.
- arepublicadoceu 4y agoI realise now that I was not clear on my post. Using TOTP or second factor is useful for those heathens that insist in using cloud based service for password manager (I'm one). Not for local keepass/pass synced by syncthing/rsync/ssh etc. I treat my kdbx as a single password encrypted backup of my bitwarden vault on my computer and external hard-drive. I care much less about second factor if it's something offline on my computer than something accessible by a web interface to anyone in the world.
- atriix 4y agoWell my password manager don't have an account to begin with, neither does my TOTP manager. And depending on risk assesment for a given site/account, letting the password manager do some doubble duty as TOTP manager as a convinience is fine, especially if the alternetive outcome would be to not enable TOTP due to the annoyance.
- unethical_ban 4y agoIf you have a TOTP app that allows exoprts, I agree. If the individual site allows backup codes, I agree. But you first need an app that hosts your TOTP that has exportable secrets.
- theandrewbailey 4y agoA password database file is sort-of a second factor (something you have).
- andrewaylett 4y agoI use Bitwarden for TOTP, because I have become convinced that it still provides a true second factor even if both the password and the TOTP seed are in the same entry in my password manager. This is because every access to Bitwarden requires two factors: a device I've already logged in with, and either the passphrase or a biometric unlock. Bootstrapping a new device requires the passphrase and a token.