Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A better way to mitigate lockout risk is to use a 2FA mule:

https://kozubik.com/items/2famule/



If someone is locked out of their password vault, they are likely also locked out of their email...


If you have literally no other option than SMS 2FA because of bad support from websites, maybe. Otherwise it's probably one of the worst options (though I suppose unlike using your main number at least it's harder to discover the number for the 2FA phone to attack it with social engineering).


Since Bitwarden can directly email 2FA codes, this arguably would be needlessly complicated in this context.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: