I don't agree. I think that having 2 separate vaults for accounts and OTPs is a simple and effective strategy. The OTP vault can simply be the encrypted exporting of the OTP app, that you save in multiple places for redundancy and you unlock only when you have to restore the vault. This approach mitigates several problems, including supply chain attacks, and you just need to manage two passwords/backups (which you have to have anyway if you manage the password manager/email otp separatly).

Of course, given the general lack of attention to this sort of thing, using a single password manager is often already an improvement and "good enough".

PS: The articile is a bit of an adv for 1Password!

Reply to this note

Please Login to reply.

Discussion

No replies yet.