Curious to see what everyone here’s opinions of this is

  • cooopsspace@infosec.pub
    link
    fedilink
    English
    arrow-up
    4
    ·
    11 months ago

    Multi factor authentication is about having multiple factors for authenticating you:

    Something you know (like a password) Something you have (with you - a hardware key, smart card or token) Something you are (biometrics, fingerprint, faceid)

    So the idea is that you’ll have two points of identification.

    But if you have your TOTP token and your generated password in the same password manager - that’s effectively only one factor of authentication.

    If you’ve gotten this far you should probably consider a WebAuthn key like the Ubikey to be the “something you have”.