If your 2FA code is as autocompletable as your password, is it really a second factor?
It is access requirement for something else, which fulfills the criteria of 2FA.
In this case, there is requirement to access the browser and phone.
11–20 of 56 posts
If your 2FA code is as autocompletable as your password, is it really a second factor?
It is access requirement for something else, which fulfills the criteria of 2FA.
In this case, there is requirement to access the browser and phone.
Very cool! Will you also add support for secret based 2FA codes, similar to Authy / Google Authenticator? It would be incredible to have those autofill.
1Password already has support for this. Some would argue that you're defeating the purpose of 2FA if it's stored in the same way as your password, but it is pleasant.
If your 2FA code is as autocompletable as your password, is it really a second factor?
2FA code (rng seed) can be stored to password managers directly as well. It is access requirement for something else, which fulfills the criteria of 2FA. In this case, there is requirement to access the browser and phone.
Very cool! Will you also add support for secret based 2FA codes, similar to Authy / Google Authenticator? It would be incredible to have those autofill.
1Password already has support for this. Some would argue that you're defeating the purpose of 2FA if it's stored in the same way as your password, but it is pleasant.
If your 2FA code is as autocompletable as your password, is it really a second factor?
2FA code (rng seed) can be stored to password managers directly as well. It is access requirement for something else, which fulfills the criteria of 2FA. In this case, there is requirement to access the browser and phone.
I guess it’s still safe against leaking of your password only.
If your 2FA code is as autocompletable as your password, is it really a second factor?
If your computer is compromised, the 2FA should be somewhere else, not in a keychain.
This is why I like Yubikey and other forms of 2FA (phone based TOTP, mostly).
[flagged]