|
|
|
|
|
by arinlen
1405 days ago
|
|
> Why should I have to go through all that faff when I have a perfectly good password manager? If you are not using dedicated special-purpose email addresses with specific services, you're already grossly mismanaging your online safety. Think about it for a second: how does your password manager help you if your email password gets leaked? |
|
> how does your password manager help you if your email password gets leaked?
You still need my TOTP codes in my case at least, which conveniently are stored in my password manager. Is it perfectly secure? No, of course it's not, but frankly my risk profile isn't worrying about a targeted attack on me and my password manager, it's worrying about leaked shared credentials.
Side note, I also get a push notification on my phone whenever a new device logs on, so unless the attack is _extremely_ targeted, well timed and they know what they want, Its not a risk for me.