TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Best password manager, 2FA, and recovery code strategy?

2 pointsby gtbcbover 1 year ago
I like the idea of using a normal-ish, commercial password manager; however, I don&#x27;t like the idea of also having 2FA and recovery codes in that same password manager in case another LastPass situation happens.<p>What would you all recommend? 2 or 3 different password managers (or perhaps 2 or 3 different accounts with the same password manager?), one for passwords, and one for 2FA and potentially another one for recovery codes? Any best practice resources &#x2F; websites?<p>I feel like I&#x27;ve read on HN people doing some really complicated stuff, and I&#x27;m not super interested in that. I want something that balances convenience with security and not having all my eggs in one basket. Convenience includes being able to relatively easily access the separate 2FA codes as some sites now require them all the time.<p>One situation I&#x27;m concerned with is someone stealing my phone at gunpoint and demanding the passcode and &#x2F; or my password manager password. That would basically give them keys to the castle.<p>Additionally, if someone was mildly sophisticated, they could kidnap you, demand relevant passwords, but also make you go through your email searching for the various banks, and then forcing you to login to those and drain the accounts.<p>Lastly, would you all support adding a PIN code to your phone to prevent stealing of your eSIM?

1 comment

akerl_over 1 year ago
Targeted kidnapping and coercion to extract passwords is not part of the threat model for the overwhelming majority of people.<p>Likewise for being forced to unlock your phone at gunpoint to get at your accounts. People who are committing individual armed robbery to get valuables are doing it for the raw goods, not as an input to get into your accounts. They’re gonna take the phone, try to flip it, then burn up some charges on your credit cards before the bank cancels them.<p>I have passwords in 1password. MFA for sites I don’t really care about goes in 1password, as do recovery codes for those accounts. Any accounts that matter, MFA is on my phone and yubikey. Recovery codes are on index cards in a physical safe.
评论 #38810023 未加载