Hacker News new | ask | show | jobs
by ggm 2687 days ago
You have to ask yourself what's the primary threat. Yes,the point in strong sense of a second factor is a fully independent test. But the actual threat it mostly protects against is credentials threats. Not loss of devices or compromise of a keystore. SMS as second factor is way way worse because of the porting problem. Otp inside 1password is a compromise but it protects against the primary threat.

If you crypt your disk and use a good passphrase or a long pin and passphrase on a phone you are not that badly exposed.