3 ms·
> But if someone compromises your phone, they are already physically close. I don't know how to respond nicely to such an idiotic comment.
by TacticalCoder 2y ago
> But if someone compromises your phone, they are already physically close.
I don't know how to respond nicely to such an idiotic comment.
- jorvi 2y agoHow else would they compromise your phone? They're not going to be able to login to your Apple/Google account due to.. drum roll.. 2FA. The only idiot is you.
- Izkata 2y agoYou said this above: > They can log in to your password manager, but since they don't have access to your TOTPs, they can't login anywhere (or anywhere important, if you do what I do). This means they can't breach your Apple/Google account or 2FA either. This is wrong. TOTP apps like Authy have no authentication. Open the app and the codes are just there, visible to anyone without having unlock it.
- jorvi 2y agoOkay, let me put it less ambiguous: If they login to your password manager in a remote location, from their own device, they can't get to your TOTPs if you store them separately in an app on your phone. > TOTP apps like Authy have no authentication. This is just wrong. My Authy is locked with separate pincode+FaceID and has been for years. And in general, if they are in your physical phone (presumably because they know your pincode), they can wreak all sorts of havoc already. They can add themselves as an alternative recovery e-mail to your Apple ID / Google account. Perhaps they can even disable TOTP 2FA via SMS, although I am not to certain of that.