Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To be fair, TOTP should be a separate device to fulfil the criteria of actually being 2FA.


I totally agree, however there are some low-criticality services where 2FA is a burden and having it in your main password manager app is a tradeoff worth consideration. Definitely NOT your primary email address.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: