Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Several comments here suggesting that using password managers for TOTP defeats the purpose of TOTP as a second factor. I don't agree.

I strongly prefer other factors (U2F/FIDO(2)/WebAuthn/Passkeys/whatever) but unfortunately TOTP is still extremely prevalent. Worse is when only a single secondary factor can be registered, in which case even if something other than SMS or TOTP is available, I slightly bias away from hardware security tokens in order to have a clear recovery path. I can at least back up most TOTP keys.

I agree that having a second vault for TOTP seems superior but from a UX and recovery perspective it's not so clear. Are both vaults available on all devices? Are they usually unlocked simultaneously? Is it likely that one vault but not the other would be stolen? Or you have a separate device or air-gap and now the usability adds friction. It seems like diminishing returns.

Conversely a single vault still offers significant protection from many attack vectors, including keyloggers and phishing. Even if access is obtained via MITM'ing a TOTP, the blast radius is often limited to a single session. Many services have poor session security, once established, but many do not. And in my experience it's still nearly impossible to get rid of SMS 2FA.

TOTP is almost always strictly better than SMS 2FA, and storing your TOTP keys alongside your passwords doesn't really diminish the effectiveness of TOTP very much at all. Unless you have the keys themselves exposed, they're still closer to "something you have" than "something you know", at least from where I'm sitting.

Their main weakness is that they can be backed up or copied at all, as well as MITM'd. How I securely store them doesn't have much impact.



> Their main weakness is that they can be backed up or copied at all

Which is also a major strength. I've had the experience of a phone app losing all of my TOTP information, and spending a long while having to use the recovery paths of various websites. After that experience, I want my second factor to be something I can back up and restore.

That'll continue to be true until either all websites reliably accept multiple 2FA devices (e.g. register multiple hardware keys) or I can buy multiple redundant hardware devices that produce the same TOTP codes so I can register "one" device with a site and still have a backup.

I wish the Firefox password manager had builtin TOTP support.


Most of the security benefits of TOTP is really for the service providers. Service providers get blamed when users are hacked because they used the same weak password across multiple websites. With TOTP service provider chooses the key the codes are derrived from, so user cannot choose a stupid one.

Most of the other threats that people talk about TOTP fixing are movie plot threats and not ones that happen in the real world to ordinary people. The only major exception is that webauthn prevents phishing, but TOTP cannot help with that.


Arguably storing TOTP tokens in your password manager does provide a level of protection against phishing.

You might fool me with that phishing page, but you won't fool my password manager's autofill. It would have to be full on MITM or DNS poisoning for that to work, which is already more of a movie plot.


Sure, but that is true of your normal password as well. It doesn't add any additional security.


1. using password managers for TOTP defeats the purpose of TOTP as a second factor

2. using password managers for TOTP is useful

Both can be true simultaneously.

The point of "something you have" is that it is "literally infeasible" to compromise your account without physically robbing you of your yubikey-equivalent. That automatically excludes >99% of the population that aren't within X miles of you from being able to potentially attack you.

Using this definition, both SMS and TOTP already fail, but at least one can approximate it by storing the TOTP on a physical device in a way that blocks casual export.

If you store it in a (non-local/backed up) password manager, you completely give up the pretense that "it is impossible to compromise your account without physically robbing you of your yubikey-equivalent". Someone from across the world can now compromise you without leaving their room.

Now again, just because it doesn't meet the "2FA threshold", doesn't make it useless. But it is also true that it doesn't provide the level of security that 2FA is supposed to provide.


Unless you were using LastPass and their Authenticator app. When they admitted that there had been unauthorized access to their storage and databases that had users vaults, what they failed to mention publicly (but which they finally told me after persistent questioning) was that the TOTP seeds were also part of the breach.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: