Is this some sort of a convenience feature hidden behind a paywall to justify purchasing their subscriptions or does generating the codes actually cost money? If the latter is the case, how do applications like Aegis do it free of cost?

  • ddnomad@infosec.pub
    link
    fedilink
    arrow-up
    18
    arrow-down
    7
    ·
    2 years ago

    Please don’t use your password manager for TOTP tokens. It is called two factor authentication for a reason.

    • beeb@lemm.ee
      link
      fedilink
      arrow-up
      21
      ·
      2 years ago

      The reason that 2fa exists is not to protect you if someone gets their hands on your device. It’s to protect you if your “static” credentials leaked from a providers’ database or you otherwise got phished. Using a password manager to handle mfa is totally reasonable.

      • 4am@lemm.ee
        link
        fedilink
        arrow-up
        3
        ·
        2 years ago

        If you are really worried about the password manager being an intrusion vector, secure your vault with a hardware key.

        • Acters@lemmy.world
          link
          fedilink
          arrow-up
          4
          ·
          2 years ago

          You can be paranoid and split the two, but most people(99%) will be perfectly fine with KeePass.

      • ddnomad@infosec.pub
        link
        fedilink
        arrow-up
        1
        ·
        2 years ago

        It is reasonable yet subpar under a threat model where you do not trust any single provider, which is a model I find appropriate most of the time.

    • auth@lemmy.ml
      link
      fedilink
      arrow-up
      2
      ·
      2 years ago

      I do that mainly for accounts I don’t care about but either way it does increase security as compared to just a password in many cases… I just wish that some of these services didn’t require TOTP