Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How about you allow me to turn off the second factor if I have a password manager, because I'm way more concerned about loosing my second factor and getting locked out of my account than someone somehow getting into my password manager.


I personally use 1password for authenticator codes - highly recommend if you haven't seen it: https://support.1password.com/one-time-passwords/

Edit: Didn't answer the actual question - it's something we can look into. My instinct is that offering this wouldn't drastically change the security model, as long as we can be confident your password actually came from a secure password manager. Since some password managers (like 1password) are very strongly tied to devices, I think your ability to retrieve a password from it is a reasonable proxy for a possession factor.

It's definitely something I'd want to read more literature on before building. That's just my instinct, and I'm half expecting someone on HN to share the attack I'm forgetting :)


But doesn't this completely defeat the purpose of the codes, since they're no longer a second factor? I'd rather just not have the codes, as they're still a significant annoyance with next to zero benefit.


There are still some benefits. Your password can probably be bypassed with a "forgot password" flow while the TOTP code cannot.

Aside from that, though, I think it's reasonable to argue that the security of password+code in 1password is equivalent to just password in 1password.


If someone scrapes your clipboard or records your screen for example, this still adds a second layer of protection.


They can't scrape the clipboard because of autofill, and they can't record the screen because passwords appear as ******.


> passwords appear as hunter2.

You should be careful about copy pasting your password on the internet.


Huh? That’s not what I wrote...



Thank you. It was a clever reference on your part, I just hadn't seen it before. :)


Hehe you learn something new every day




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: