Is this some sort of a convenience feature hidden behind a paywall to justify purchasing their subscriptions or does generating the codes actually cost money? If the latter is the case, how do applications like Aegis do it free of cost?

  • ddnomad@infosec.pub
    ·
    1 year ago

    Please don’t use your password manager for TOTP tokens. It is called two factor authentication for a reason.

    • beeb@lemm.ee
      ·
      1 year ago

      The reason that 2fa exists is not to protect you if someone gets their hands on your device. It's to protect you if your "static" credentials leaked from a providers' database or you otherwise got phished. Using a password manager to handle mfa is totally reasonable.

      • 4am@lemm.ee
        ·
        1 year ago

        If you are really worried about the password manager being an intrusion vector, secure your vault with a hardware key.

      • ddnomad@infosec.pub
        ·
        edit-2
        1 year ago

        It is reasonable yet subpar under a threat model where you do not trust any single provider, which is a model I find appropriate most of the time.

    • auth@lemmy.ml
      ·
      edit-2
      1 year ago

      I do that mainly for accounts I don't care about but either way it does increase security as compared to just a password in many cases..... I just wish that some of these services didn't require TOTP