Hacker News new | ask | show | jobs
by conception 877 days ago
This also rubs me the wrong way but at least on 1Password it’s cumbersome enough to add a device to your account that you still need to have something as a factor - an authed device on your account. So the attacker would need one of those and your master password to get at the otp. It’s not the highest level of security but it’s not quite eliminating things back to single factor.