3 ms·
definitely not, adding in a second factor such as fido u2f provides unique passwords per domain, which levels up security against phishing attacks!
by stees 3y ago
definitely not, adding in a second factor such as fido u2f provides unique passwords per domain, which levels up security against phishing attacks!
- Detrytus 3y agoThe problem I have with hardware based authentication, such as Yubikey is that it's a physical thing that can be taken away from you (or just break, or get lost), which makes me nervous. Maybe it's stupid, but the scenario I always have in mind is one from "Bourne Identity" movie, with Jason Bourne found in the sea, with nothing on him, no wallet, no phone. And it's not far fetched scenario either: I travel a lot, internationally, so I always imagine being mugged, having my phone and wallet taken away from me. Being able to login to my accounts, and more importantly, access my money in the bank with nothing but a password stored in my brain is important to me.
- mysteria 3y agoA lot of places with hardware authentication will provide a recovery key you can store somewhere you can access (e.g. as an encrypted file on an cloud storage service with no 2FA/geolockouts). Obviously the passwords for the file and the service are memorized. If all your possessions are stolen you could say use a borrowed computer to access that file and bootstrap yourself. For services with TOTP you can store the secret in that encrypted file, so you can reload it back into your authenticator app. Or you could just use a Keepass file or similar which would store all the passwords and keys in a single encrypted binary.
- LegionMammal978 3y ago> For services with TOTP you can store the secret in that encrypted file, so you can reload it back into your authenticator app. Though you do have to be very circumspect in choosing that app: the news of Authy's desktop app (which you could pull the tokens from) being discontinued is still fresh in my mind.
- Detrytus 3y agoI recently discovered that KeePassX can be used to generate TOTP, and it is open source
- EvanAnderson 3y ago> ...adding in a second factor such as fido u2f provides unique passwords per domain... Properly using a password manager provides unique passwords per domain too.
- pepa65 3y agoPasswords can be backed up in many places, this is much harder with the fido u2f.