3 ms·
If the authentication database is being breached, presumably the 2FA shared secret is going to be in the same database. Constructing the 2FA code would be triv
by davis_m 11y ago
If the authentication database is being breached, presumably the 2FA shared secret is going to be in the same database. Constructing the 2FA code would be trivial. After all, the server needs a way to check that a given 2FA code is correct for an authenticating user, so there has to be some way to generate those as well.
It would help protect against any other sites that you use the same password on, with a different 2FA shared secret.
- chrislaco 11y agoIf you use Google Authenticator. I would assume this is not the case w/ Yubi.
- chrislaco 11y agoIf you use Google Authenticator. I would assume this is not the case w/ Yubi.
- flurpitude 11y agoSo it would be wise to change the LastPass master password and also regenerate the Google Authenticator key. LastPass does enable you to regenerate this key from the account settings page.