4 ms·
> essentially nullifying the second factor Not totally. It still protects from the password being disclosed via other means (e.g. server db leak).
by amarshall 3y ago
> essentially nullifying the second factor
Not totally. It still protects from the password being disclosed via other means (e.g. server db leak).
- e12e 3y agoWell, no - if we assume server password db leak includes leaking totp shared secret... But that is also why I'm not overly concerned by the bitwarden model: in client compromise (ie phone), attacker gets both password and totp secret. But so too in many examples of server compromise. Seperate totp app doesn't really mitigate any risk factors - but a seperate hw token/device do. You could have 2fa only on phone, password manager only on desktop - but then logging in anywhere on your phone is inconvenient. Then again: "Security is not a convenience".