Hacker News new | ask | show | jobs
by yonatan8070 762 days ago
If a user keeps their credentials in a notebook and it got stolen, the TOTP check can be the difference between the attacker getting in, and the user being notified and changing their password
1 comments

Unfortunately these days it’s even easier with password managers containing all three (user, pass, token)
The difference being the notebook is paper and easily read, while the password manager is... quite a bit harder.
I want to believe users who use a password manager are also technically literate enough to secure it properly
Me too, but my day job means I handle a bit of secops, password managers are rolled out as security tools to users operating in enterprises where things like mandating people don't keep their passwords on a sticky note on their monitor is usually step one...