Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If your password is compromised they still don't have access to your OTP, so 2 factor. If your password manager is compromised then they have both, 1 factor.

I'm no math wiz but pretty sure that makes it a 1.5 factor



Right, presumably with a password manager you’re using a totally random string as your password too, coupled with different passwords for each site. so there are a combination of factors that make it still much more secure than just “both factors in one place” since neither factors can easily be guessed.

The main threat vector would be, as you mentioned, compromise of the actual password manager.

As far as I can tell, 1Password’s end to end encrypted architecture makes this less probable.

That would reduce the main risks to our actual devices.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: