4 ms·
> For the majority of people, storing TOTP in 1Password is well within their risk tolerance. There will always be those of you who will trade that convenience b
by leftcenterright 2y ago
> For the majority of people, storing TOTP in 1Password is well within their risk tolerance. There will always be those of you who will trade that convenience because you want or require the added protection of true 2FA. And to those faithful hardware key crew members: Think of your true second factor as less “extra layer of security,” and more granular protection that will apply only if you’re subject to certain forms of attack.
this is the crux really. Especially when a web based password manager is in use [0], this is not at all within risk tolerance for people really striving for a long-term threat model which they do not need to revisit every couple of years.
Buying multiple hardware tokens and keeping one authenticator/TOTP app on phone is very practical the best you can do and it is secure, loss-proof and will last for a long time. Most services allow you to add multiple types of 2FA devices.
0. https://lock.cmpxchg8b.com/passmgrs.html https://lock.cmpxchg8b.com/passmgrs.html