Replies (25)

Diyana's avatar
Diyana 1 year ago
It's on my to do to fix this up...
Assume all passwords are compromised. No pvt key material online, ever. Analog with signing devices only.
Troy's avatar
Troy 1 year ago
I only reuse other people's passwords.
So, you want the state to have access to everyone's private keys? /sarcasm
If my login information is breached, I'm protected by my 2FA codes. If my 2FA codes are breached, my login information are still safe. 2FA is meant to provide extra security. This is pointless if your login info and 2FA info are in the same place.
A.A.Ron's avatar
A.A.Ron 1 year ago
I have had the same ATM pin number since 1998. I have changed banks 4 times.
what if you put 2fa in the manager but the 2fa for the manager is in a different authentication software? convenient and more secure πŸ€”
However, put the most important 2FA in a separate app. Leave the Netflix/Amazon 2FA in the password manager. Be aware: likely the most important 2FA are those for your email accounts. All your email accounts.
I need to look into Bitwarden's security model more, but I'd probably only feel comfortable running it locally unless they have a comparable design to 1Password. Aside from their security principles, the other thing i really love about 1Password is how multiplatform they are. Wonderful apps for Windows, Mac, and Linux, and they have a cli and SSH agent i use in Linux.
Absolutely terrifying. I wonder πŸ‘ they imagined πŸ˜€ gods, demons and monsters battling in the 🌈 heavens and seas.
↑