Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't understand how it's not a security degredation. The point of TOTP is to make access of the service dependant on something you must have phsyically (and isolated from the internet) on you. An attacker that manages to exfiltrate 1Password data has everything they need to access the service if TOTP is part of their offering. Where as all users with TOTP on their phone would have an additional layer of protection.

Even by that blog post, they have to go out of their way and clarify that using this feature means you are not longer using two-factor authentication.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: