4 ms·
If your password manager is hacked, but your TOTP info is offline, how is this not better that having TOTP info in your password manager? Also not sure how sync
by chkaloon 3y ago
If your password manager is hacked, but your TOTP info is offline, how is this not better that having TOTP info in your password manager? Also not sure how syncing through a cloud drive is any better than a cloud password manager.
- SturgeonsLaw 3y ago> Also not sure how syncing through a cloud drive is any better than a cloud password manager. The private keys stay on your machine
- chkaloon 3y agoNot if you're using a commercial cloud drive
- djha-skin 3y agoYour point about separating TOTP being more secure is a good one and I acknowledge it. I simply find storing the TOTP together with the password manager to be a reasonable compromise between security and convenience. Sinking through a cloud drive is better because it diffuses the value proposition of hacking the cloud drive. If someone hacks The cloud provider they are likely to find a bunch of ripped videos and pictures of children and cats, with the occasional sensitive file here and there. Thus it makes less sense as a hacking target while still having lots of the same protections and professional oversight as any other cloud provider. The value proposition of hacking a password manager SaaS is much higher so it becomes much more worth someone's time to hit. It's like the difference between storing gold in a lock box in a bank and storing gold in a lockbox in a storage rental facility. Storage rental still has guards and locks and cameras, but will not attract the attention of dedicated, organize efforts to extract value like the bank will.
- chkaloon 3y agoGood points. I keep Auth backups in my pw manager for convenience also, just because I don't know of a better way other than printing the qr code and stuffing in my desk. I'm not worried about a general cloud beach as much as I am a personal attack if someone gets hold of my phone and manages to unlock it. Then they have 2 of the 3 keys: the cloud drive, and the Auth app. All they need to do is hack the pw manager, which if they have the vault file from the cloud drive, they can brute force until the cows come home.