Hacker News new | ask | show | jobs
by harg 2008 days ago
I think it’s more of a last line of defence in case your password manager gets compromised. Especially if your pw manager also handles your TOPTs.

But if your pw manager gets compromised then that’s a pretty big problem so probably best to focus efforts on that not happening.

It could make sense for sensitive accounts like email, valuable social media etc