A
If a password manager stores your 2FA token is it still 2FA?
Vergecast listener Garfield wrote in with a question so debatable I had to quickpost it:
Password managers are starting to support 2fa passwords. Basically you can save your TOTP seed along with your password and it will generate the code for you when needed.
The question is, is that even 2fa anymore?
So the website receiving everything still perceives it as 2FA, but you, the user do not. However you’d also still need 2FA to access the password manager to circumvent another site’s 2FA which means it would technically still be 2FA.
So what do you think?
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.
Loading comments
Getting the conversation ready...











