Live data from Hacker News

Why does storing 2FA codes in your password manager make sense?

andygrunwald.com

141–147 of 147 posts

Re: Why does storing 2FA codes in your password manager make sense?

#142

Earlier quoted context omitted.

As a German I have access to words like "Moselschifffahrtspolizeimützenverordnung" and that's a mild one :)

Stupid German proving me wrong with something that most languages don't have access to. \s I'm sure German is not alone, but it is the only one I'm aware of - though with over 7000 known languages I doubt anyone knows enough to state anything with confidence.

I believe Sanskrit has some very long words like 600 Roman letters or something

Re: Why does storing 2FA codes in your password manager make sense?

#143

Earlier quoted context omitted.

The most important bit of information is missing from your post: was everyone using 2FA? If yes, then you make a relevant point.

Even if no 2FA was involved at all, it's a good answer to the scenario you were posing. I think plenty of people will have second thoughts when the password doesn't go.

The comparison here is using 2FA with external device, or putting 2FA codes into a password manager.

Any kind of experiment that doesn't involve 2FA at all is not relevant for this comparison.

Re: Why does storing 2FA codes in your password manager make sense?

#144

Earlier quoted context omitted.

Even if no 2FA was involved at all, it's a good answer to the scenario you were posing. I think plenty of people will have second thoughts when the password doesn't go.

The comparison here is using 2FA with external device, or putting 2FA codes into a password manager. Any kind of experiment that doesn't involve 2FA at all is not relevant for this comparison.

The anecdote provides evidence for people that are initially fooled by a phishing attack but aren't fooled enough to manually copy-paste credentials when autofill doesn't work.

Your argument about 2FA depends on how many of those people there are.

Therefore the anecdote is quite relevant, indirectly.

Re: Why does storing 2FA codes in your password manager make sense?

#145

Earlier quoted context omitted.

The comparison here is using 2FA with external device, or putting 2FA codes into a password manager. Any kind of experiment that doesn't involve 2FA at all is not relevant for this comparison.

The anecdote provides evidence for people that are initially fooled by a phishing attack but aren't fooled enough to manually copy-paste credentials when autofill doesn't work. Your argument about 2FA depends on how many of those people there are. Therefore the anecdote is quite relevant, indirectly.

[deleted]

Re: Why does storing 2FA codes in your password manager make sense?

#146

Earlier quoted context omitted.

If you store both in one place, it's similar to 1FA. In such case it's a lot better to just use passkeys (where supported).

Good point about it being similar to passkeys. But why would it be better to use passkeys? Because don't sites with passkeys generally still allow you to fall back to password, since it's common for people to lose their phone and then lose their passkey? Whereas sites with 2FA obviously don't, and have more complicated/secure recovery mechanisms? So seems to me like 2FA (TOTP's) are currently vastly better in practic…

Most sites that allow a passkey also require you setup 2FA with your password when enabling passkeys. Which, unless you also set up an alternative method like TOTP, would also be your passkey.

So ironically, your options would be your passkey, or your password+passkey/FIDO key (in 2FA mode).

Re: Why does storing 2FA codes in your password manager make sense?

#147

Using 1Password requires me to use one of my devices to add a device to my account. If someone has my password and my device how will a separate app help me in this case? Honest question as the 1password model seems to be “something you know and something you have”.

If someone hacks 1Password, they will get access to all your accounts. Whereas if you moved TOTP off 1Password, that hacker would no longer be able to access your accounts.

If someone hacks 1Password, they get an encrypted vault. 1Password has no access to my passwords. There is no recovery mechanism without the encryption keys or a device on the account.
Post reply on HN