3 ms·
> TOTP + password manager is more convenient (and more online) than yubikey, in my opinion. Especially convenient with a browser plugin. More convenient than y
by kenmacd 3y ago
> TOTP + password manager is more convenient (and more online) than yubikey, in my opinion. Especially convenient with a browser plugin.
More convenient than yubikey webauthn, or just yubikey TOTP? Personally I find tapping my yubikey much easier than any 'enter the code' 2FA.
Also it should be noted that storing your TOTP secret in the same place as your password means you're one malware attack away from losing access to that account. While this risk may be acceptable for many accounts, it should at least be considered.
- djha-skin 3y agoThe security implications are indeed a debate, but really any attack on the password manager is a huge security problem anyway so you might as well store the TOTP information there. One way to mitigate this is to use offline password managers such as keepassXC (which I use) and non-proprietary sync stuff such as syncthing (but I just use a cloud drive provider). Entering a code is easy because of the password manager plug in. I don't have to find the Key with my finger, I just have to click with the mouse. Much easier.
- chkaloon 3y agoIf your password manager is hacked, but your TOTP info is offline, how is this not better that having TOTP info in your password manager? Also not sure how syncing through a cloud drive is any better than a cloud password manager.
- SturgeonsLaw 3y ago> Also not sure how syncing through a cloud drive is any better than a cloud password manager. The private keys stay on your machine
- chkaloon 3y agoNot if you're using a commercial cloud drive
- djha-skin 3y agoYour point about separating TOTP being more secure is a good one and I acknowledge it. I simply find storing the TOTP together with the password manager to be a reasonable compromise between security and convenience. Sinking through a cloud drive is better because it diffuses the value proposition of hacking the cloud drive. If someone hacks The cloud provider they are likely to find a bunch of ripped videos and pictures of children and cats, with the occasional sensitive file here and there. Thus it makes less sense as a hacking target while still having lots of the same protections and professional oversight as any other cloud provider. The value proposition of hacking a password manager SaaS is much higher so it becomes much more worth someone's time to hit. It's like the difference between storing gold in a lock box in a bank and storing gold in a lockbox in a storage rental facility. Storage rental still has guards and locks and cameras, but will not attract the attention of dedicated, organize efforts to extract value like the bank will.
- chkaloon 3y agoGood points. I keep Auth backups in my pw manager for convenience also, just because I don't know of a better way other than printing the qr code and stuffing in my desk. I'm not worried about a general cloud beach as much as I am a personal attack if someone gets hold of my phone and manages to unlock it. Then they have 2 of the 3 keys: the cloud drive, and the Auth app. All they need to do is hack the pw manager, which if they have the vault file from the cloud drive, they can brute force until the cows come home.