Hacker News new | ask | show | jobs
by microtonal 4482 days ago
It's a bit of an improvement. On the other hand, if that one account is hacked, it gives access to everything else as well. Moreover, you can even get a list of applications/sites tied to that account. Which makes it arguably even less secure.

If we want people to be safer, we should learn them how to use a password manager to generate a unique password for every site.

And since access to passwords requires two things (the password to the password manager and the password database), it's arguably more secure, even with a weak password.

1 comments

I use Google Two-Factor authentication. I need my password, and my phone.

If I root your box, and watch you type, I have the password to your password manager, and the password database.

Arguably, if you root someone's box you could install a modified TLS stack that would allow for a MITM attack to capture the 2FA login flow. (But this would be obviously a little more difficult)
I have a friend that this happened to. I unfortunately cannot elaborate.