1001
What a life (media.piefed.world)
you are viewing a single comment's thread
view the rest of the comments
[-] Honytawk@feddit.nl 3 points 6 hours ago

Wouldn't recommend putting your MFA in your password manager. You'd only have one attack entry point.

The point of MFA is that you have multiple, so if one ever gets breached, they still wouldn't be able to get into your accounts.

Now, if they can get into your password manager, it is over.

Though keepass is a pretty good local one, can recommend.

[-] jsomae@lemmy.ml 1 points 44 minutes ago* (last edited 42 minutes ago)

TOTP ≠ MFA.

The purpose of TOTP is to use 1-time codes instead of (or in addition to) passwords, and doesn't require multiple devices.

The purpose of MFA is to ensure the user uses multiple devices to log in. In practice, MFA isn't usually implemented correctly, as it only requires a phone and no other device to log in, so it's not true MFA. MFA is sometimes implemented with RFC 6238 (TOTP), but for example getting a text message or email with a log-in code is not that.

Your password manager should use a secure password so that attackers can't get into it. It's more secure than a phone, which often use few-digit passwords or, god forbid, fingerprints or face scans to unlock.

this post was submitted on 26 Aug 2025
1001 points (100.0% liked)

memes

17055 readers
2704 users here now

Community rules

1. Be civilNo trolling, bigotry or other insulting / annoying behaviour

2. No politicsThis is non-politics community. For political memes please go to !politicalmemes@lemmy.world

3. No recent repostsCheck for reposts when posting a meme, you can only repost after 1 month

4. No botsNo bots without the express approval of the mods or the admins

5. No Spam/Ads/AI SlopNo advertisements or spam. This is an instance rule and the only way to live. We also consider AI slop to be spam in this community and is subject to removal.

A collection of some classic Lemmy memes for your enjoyment

Sister communities

founded 2 years ago
MODERATORS