Hacker News new | ask | show | jobs
by elops 3203 days ago
Storing seed for 2FA on your phone (google authenticator) leaves you vulnerable to anyone who compromises your phone. If someone compromised your phone, your likely would not know they are generating the same 2FA codes as you do. To tackle this problem you could store your 2FA secrets on secure device (e.g. Yubikey NEO) and use phone as display.

Lastpass is cloud service and they had some issues in the past, I consider more offline/app approach for password manager as bit more secure alternative.