logoalt Hacker News

schrodingerlast Thursday at 11:23 PM2 repliesview on HN

That’s a good point.

Maybe a good compromise is to use 1pw for most TOTP but keep your gmail / iCloud and a few others in an iPhone only app?

Gmail is what scares me the most. It’s basically keys to the kingdom.


Replies

everybodyknowsyesterday at 2:46 AM

> Gmail

We might all do well to remind F&F to print out account recovery codes, and then put some thought into where they'll be safe.

frantathefrantayesterday at 3:02 AM

I settled on that after trying to be extra careful with TOTP. Now my split is 95% of passwords, TOTP codes and passkeys in 1Password, 5% (really important stuff like email) in an offline KeePass DB + passkeys on Yubikeys.