|
|
|
|
|
by 8cvor6j844qw_d6
44 days ago
|
|
> Strong support for the strategy of not putting your TOTP/MFA in your password manager Agreed, but I think using the same device to access your password manager and for dev is asking for trouble in the first place. Password managers assumes a non-compromised device. I don't think there exist a password manager that is explicitly designed for a compromised/hostile device. A password manager + built-in TOTP on a dedicated device is fine for most general usage. Important TOTPs can go to Yubikeys. |
|
That seems somewhat unrealistic? There are many passwords you need to use as part of dev work.