|
|
|
|
|
by jedberg
2893 days ago
|
|
Normally I would reply back and explain, but you know more about this than I do, so instead I will ask a question. Does it not protect against your password being compromised in some other channel? Sure you're probably not reusing passwords, but what if they compromised it some other way? What if the website had a flaw that allowed someone to exfiltrate plaintext passwords but not get at other application data? Or to put it another way, if you're using a password manager, why use TPOP codes at all if you believe there are no other attack vectors to get the password that TPOP protects against? |
|
TOTP is very useful! Just use a TOTP authenticator app on your phone, and don't put them in 1Password.