This is absolutely perfect for a use case that I've seen a lot: shared test accounts. Eg our app connects to external service X, so we have a staging account set up such that the staging version of our app can operate. But service X values security and requires 2fa on all accounts. This is really annoying, especially if service X is expensive and charges per seat. We don't want to pay for a seat for all of our develo…
Do you know 1password handles storing mfa codes?
Show HN: Generate shared 2FA codes for your entire team
41–43 of 43 posts
Re: Show HN: Generate shared 2FA codes for your entire team
#42Re: Show HN: Generate shared 2FA codes for your entire team
#43Like most of the services popping up around 2FA, now that 2FA is popular: this essentially removes one of the factors. Whether you're making one of the factors available to everyone on Slack, or putting it next to the password in LastPass, the result is the same, you delete the security benefits of 2FA.
Most people have their phone as a 2FA device, but they will login to websites/services on their phone anyway. Would you suggest preventing logins from phones? The REAL benefit of TOTP is that it's time sensitive. If someone does have your password and TOTP code over the wire, they cannot repeat the attack. I think this service is fine, but as others have pointed our you're giving away for TOTP secret to a third party…
Using a password manager on your phone turns it into just something you own.