Hacker News new | ask | show | jobs
by mdavidn 1910 days ago
The alternative is to navigate 100 separate token reset processes if you ever lose your phone and all of its TOTP tokens.
1 comments

Or just keep them somewhere that isn’t directly beside the password?

I have my password in a password database, and my TOTP tokens on my phone and a Yubikey.

I have a second “break glass in case of emergency” password database that contains TOTP secrets for all my most essential accounts and a backup of the key loaded on my Yubikey.