Hacker News new | ask | show | jobs
by arubania2 1526 days ago
> and never use your passwords on the phone you are using as 2FA

Notably, this also involves not logging into the same email account that you use for signups - it would allow the attacker to bypass the password manager completely by requesting a password reset.

I guess you could solve this by having one email address for signups and another to communicate with people, but you would still be giving up email notifications (such as “your order has been shipped”) delivered to your phone.