4 ms·
I'm not sure what service you're using, so this might or might not apply to you: Consider that some password managers use MFA to allow you to connect to their o
by sebk 4y ago
I'm not sure what service you're using, so this might or might not apply to you:
Consider that some password managers use MFA to allow you to connect to their online service that will download a synced, encrypted copy of your password vault, but the vault itself is only wrapped with a key derived from your master password.
If someone was to obtain a copy of your vault, decrypting it would be trivial with a weak or compromised master password in that case.
CTAP supports an extension called hmac-secret that would allow you encrypt your vault, which would mitigate this issue (While introducing others potentially -- for instance, hmac-secret does not require user verification so anyone with your yubikey could decrypt it). Of course there are other mechanisms to encrypt a vault other than a key derived from a password that you can use with a Yubikey, like PGP, but I don't know of any commercial password manager that does it that way.