Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If you use oathtool on your laptop, and the password is stored there as well, you're back to 1FA... that can be fine if that's what you want.

A lot of the time that is what I want. 2FA is pretty overkill for low-importance accounts if you're using a long random password anyway. But some services make it mandatory.





I quite like TOTP for this reason - it's much less annoying to autofill TOTP than to retrieve a one-time code from SMS or email.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: