|
|
|
|
|
by nicce
297 days ago
|
|
It is not necessarily 1FA even if just use the laptop. One password could be leaked and if the password alone gives the access, that is 1FA. If the combination of two tokens forces the each login require access to that laptop and you need some password to unlock the password vault, this adds 2FA layers to services which are not the password manager. |
|
Either your laptop is compromised or the server. In either case, if they get access to the password, they also get access to the 2FA secret if that resides in this vault together with the password. Just a password alone is safer than 2FA alone because that at least gets hashed and isn't stored in plain text on the server side