1
Ask HN: Do you use your password manager to generate MFA codes?
Certain password managers like 1Password offer the ability to generate MFA tokens within the same app. While that is certainly convenient, doesn’t it defeat the purpose of MFA altogether?
I have found some posts[1][2] indicating that it may not be as risky as I think, BUT I wonder if there is more to the story. Thoughts?
[1] https://blog.1password.com/totp-for-1password-users/
[2] https://security.stackexchange.com/questions/194142/is-it-safe-to-store-2fa-tokens-together-with-passwords-in-1password
PS. Let’s stick to software tokens for the purpose of this discussion and not debate physical vs software token generators.