6 ms·
https://news.ycombinator.com/item?id=44259556 https://news.ycombinator.com/item?id=44259556 I posted another comment explaining why 1Password Vault with both a
by InitialBP 1y ago
https://news.ycombinator.com/item?id=44259556 https://news.ycombinator.com/item?id=44259556
I posted another comment explaining why 1Password Vault with both a password and a OTP code is still secure, but in short it does not defeat the purpose. Your vault's are protected and in the situation where someone gets access to your vault it's most likely to be full access to your computer at which point they have other viable methods to get access to a specific service you use.
- jascha_eng 1y agoIsn't the whole point of 2fa that if someone gets access to my computer they can't do shit because they'd need my phone too?
- InitialBP 1y agoThe “whole point” of 2fa is that even if someone knows your password they cannot login with just credentials. Compromising or stealing a device is a significant escalation from guessing passwords.
- 0cf8612b2e1e 1y agoIt is also more obvious when your device has been stolen vs just the password.