Hacker News new | ask | show | jobs
by briHass 1082 days ago
Fair enough. I stopped using it right around the time (~2 years ago?) when they finally added the ability to do an export. At that time, the compelling reason to use alternative TOTP apps was the ability to sync the secrets. I assume this feature was driven mostly because of said alternatives, rather than goodwill for such a simple/obvious feature.

I always did & do save a copy of the QR code or, if provided, the BASE64ed key in my PW manager. I know I'm never locked in with TOTP: I can use anything (I've written the 10 lines of code, even) to generate the code, and it can be entered manually on any device that can display the site's login page by hitting 6 digit-keys. WebAuthn needs, at minimum, the browser to remain open to integration.

1 comments

so it is not a 2nd factor any more since with your master pass anybody can get any passwords and the totp codes
Not op, but my qr codes & strings are saved in a separate keypass database, saved in a different location & using different password (saved in my brain only).
vow :) thumbs up!