logoalt Hacker News

sschuellertoday at 8:30 AM1 replyview on HN

I see everyone putting their TOTP and second factor in the same vault as their username/password. Doesn't this defeat the purpose of the second factor to some degree?


Replies

larsnystromtoday at 8:37 AM

Sure, but TOTP still defends against password leakage. So it’s still more secure than only using a password.