this post was submitted on 05 Dec 2024
7 points (88.9% liked)

Security

5072 readers
1 users here now

Confidentiality Integrity Availability

founded 5 years ago
MODERATORS
 

I store my mechanically generated passwords in 1Password. And I do not use the password in any way.

In such a case, does it make sense to activate TOTP? In my immature opinion, TOTP is only effective if you are using the same password for multiple websites. If this is incorrect, could you please tell me when TOTP would be useful?

you are viewing a single comment's thread
view the rest of the comments
[–] tomcatt360 2 points 3 weeks ago

TOTP is used to increase security by requiring potential attackers to both know your password, and have your token generating device. Usually your phone. It is useful even if you have unique passwords because the attacker needs access to both your password management solution and to your token generating device to gain access. In my opinion, it's worth setting up TOTP on all accounts that you care about.