Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If you store your OTP secrets in the same password store that also stores your regular passwords, you've just completely undermined the second factor of security.

Which, to be clear, is perfectly fine. 2fa is completely unnecessary: the increased risk of getting locked out from my accounts and the risk of using services from companies like Twilio and Google is greater than the risk of someone guessing long randomly generated passwords.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: