Hacker News new | past | comments | ask | show | jobs | submit login

TOTP implemented with 1Password is not 2FA.

All TOTP devices must store the symmetric key, yes. 1Password goes a step further and provides a UI to allow the user to simply copy the symmetric key out of the login record à la a password.

TOTP clients that make opinionated design decisions prohibiting a user from getting at the symmetric key are correct implementations.

That said, if one wants to mandate 2FA for one’s users, TOTP is not the right choice, given it allows users to do the wrong thing.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: