Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What about a Password Manager combined with 2FA? A bit of redundancy in case your master password is somehow compromised, so that you can individually still change each websites' passwords and store them in a new password manager with a different master password. The same applies if your 2FA device is stolen, you may store their recovery passwords on a separate password manager that isn't accessed as often.


What kind of "2FA"? SMS 2FA is not secure. Stand-alone device for every single service? Secure, but acquiring one is not so simple and not every service provides them. And do you really need to bother with multiple passmanagers at that point? Just store accounts you don't care about in one. For accounts you really care about, you should make strong unique password yourself and use stand-alone 2FA device.


TOTP codes?




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: