Hacker News new | ask | show | jobs
by sneak 2630 days ago
Your root AWS account should have 2FA, and storing TOTP seeds in your cloud password manager makes it 1FA.
1 comments

I have 2FA on my shared AWS account - my project partner and I both scanned the QR code at the same time. (You should be backing up your QR codes anyway in case you lose/break your primary phone; scanning it simultaneously with a secondary phone is a great approach for this.)

Even if this weren't possible, it would still be better to use 1FA than to arbitrarily pick one person to have root account access and lock the other person out simply because you "should" have 2FA.