this post was submitted on 17 Jul 2023
33 points (100.0% liked)
Privacy
32023 readers
828 users here now
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
Chat rooms
-
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I really like 1Password as both my PW manager and OTP generator. PWs and OTPs get synced across devices so I never worry about losing my phone and getting locked out of any 2FA sites. On iOS as well as desktop, 1Password can auto-fill passwords and OTP codes. Highly recommend.
Doesn’t this defeat the purpose of multi factor authentication though? If someone got access to 1Password, they could access both your password and secondary authentication code. I think it may be a better idea to keep them separate.
1Password has a blog post that talks about it here. https://blog.1password.com/1password-2fa-passwords-codes-together/
Ultimately it depends on your threat model and security vs convenience.
Pretty big “if” since I’m the only one who knows the long password, I rotate it often, and I hold the keys to encrypt everything. You’re right it’s a single point of fail but a LOT would have to go wrong for it to fail.
Edit: plus 1P supports physical 2FAs to get into the vault itself, if that helps
It could be useful if somebody somehow finds out their password, e.g. by shoulder surfing or perhas some other way.
Then their attack window is much more limited.
Paranoia, mostly 😅