Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Combined with a password manager is a pretty good combination.

So 2FA combines something you have (your phone) with something your phone knows.



Exactly! And I use 1Password so I also have the tokens on my computer, together with my passwords. Replay attacks get harder though.


I think his point was that if your password is stored on your phone, two factor authentication doesn't actually add any security because it's no longer two factor.


not if you access the site from a laptop/desktop




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: