If all of my 2FA code generators had been in 1Password I would have been truly screwed, but in a stroke of luck I had been paranoid enough to use a separate app for 2FA codes.
Why does storing 2FA codes in your password manager make sense?
11–20 of 147 posts
Re: Why does storing 2FA codes in your password manager make sense?
#12It's the same idea with using a password manager in the first place - if a password manager is going to be the thing that gets you to use secure passwords that vary across services, it's worth the tradeoff of having all of those passwords in one place, because you're much more likely to be compromised by a bad password than by a password manager leak.
Re: Why does storing 2FA codes in your password manager make sense?
#13Re: Why does storing 2FA codes in your password manager make sense?
#14I think it's a terrible idea, because it dramatically decreases the attack surface area needed to compromise accounts. 2FA is supposed to be "something you know' and "something you have"; putting your 2FA seeds into your password manager reduces your 2FA to "something you know", and , significantly worse, it's "something you know in the same place as the other thing you know". The time-variant component is still quit…
Re: Why does storing 2FA codes in your password manager make sense?
#15I think it's a terrible idea, because it dramatically decreases the attack surface area needed to compromise accounts. 2FA is supposed to be "something you know' and "something you have"; putting your 2FA seeds into your password manager reduces your 2FA to "something you know", and , significantly worse, it's "something you know in the same place as the other thing you know". The time-variant component is still quit…
Re: Why does storing 2FA codes in your password manager make sense?
#16Re: Why does storing 2FA codes in your password manager make sense?
#17https://github.com/kardianos/safekeysheet
It could be modified to also print out the otp as well if stored.
Re: Why does storing 2FA codes in your password manager make sense?
#18Re: Why does storing 2FA codes in your password manager make sense?
#19I think it's a terrible idea, because it dramatically decreases the attack surface area needed to compromise accounts. 2FA is supposed to be "something you know' and "something you have"; putting your 2FA seeds into your password manager reduces your 2FA to "something you know", and , significantly worse, it's "something you know in the same place as the other thing you know". The time-variant component is still quit…
People often skip out on actually assuming responsibility for their data and accounts. A backup system should be in place and ensuring their 2FA codes are not lost with their device is part of that taking on responsibility.
Re: Why does storing 2FA codes in your password manager make sense?
#20I think it's a terrible idea, because it dramatically decreases the attack surface area needed to compromise accounts. 2FA is supposed to be "something you know' and "something you have"; putting your 2FA seeds into your password manager reduces your 2FA to "something you know", and , significantly worse, it's "something you know in the same place as the other thing you know". The time-variant component is still quit…
The argument is "because many people, if they can't keep the data together, will elect not to use 2FA at all if given a choice."