Hacker News new | ask | show | jobs
by nicce 715 days ago
2FA code (rng seed) can be stored to password managers directly as well.

It is access requirement for something else, which fulfills the criteria of 2FA.

In this case, there is requirement to access the browser and phone.

1 comments

But if you have it in the PW manager, isn’t it moot?

I guess it’s still safe against leaking of your password only.

Yes, you're completely right.

It depends on your threat model vs usability/ease of use.