Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can make an argument for a second factor (other than hardware key) being of fairly little value to anyone using an offline password manager and generating passwords with a huge amount of entropy.

I don't think this is entirely true, and so I often use TOTP with important sites. But I'm okay with storing the TOTP key in my password manager (which encrypts the password database with a long key phrase and a key file). Even on top of the very little chance that any of my long passwords are going to get leaked or broken, I think the chance that this happens because my password manager gets hacked along with the TOTP keys (as opposed to me getting phished or a vulnerability in a website) is pretty remote.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: