Hacker News new | ask | show | jobs
by dtx1 1006 days ago
So... I just save my 2FA stuff in keepass... Works fine and can be backed up and replicated for free vs needing several yubikeys.
1 comments

This works until you get malware on your workstation.
That’s why you assign all of them random names which are recorded in a separate BitWarden store. That one only opens with a password which is “YUBIKEY”.
One can use the TPM so at least the secrets can't be mass exported. Doesn't stop keylogging individual ones of course (but a browser extension might).