Hacker News new | ask | show | jobs
by backing 1994 days ago
As any standardized way to store data, password managers and provider clouds have become target for pirates.

With 2FA instead, the password is less valuable than the 2FA secret token and its backup on different device to not get locked out.

2 comments

Real 2FA with at least 2 hardware keys is good. Shitty SMS 2FA is no good, hardware key + SMS is no good.

The big advantage to a hardware key is that if someone snatches it from you, you can go home, log in with your backup key, and disable the stolen key.

Phone-based 2FA is super vulnerable to simple phone theft, SIM swapping, phone number porting theft, and it's simply ridiculous that if you carry a laptop with you that you also need a phone. The laptop itself should be able to accomplish everything. I believe in the most powerful device in front of you should handle 100% of digital tasks including 2FA.

Yeah... but some store their 2FA backup codes in said password managers, effectively turning them into the ultimate account breach honeypots.