Authy got hacked, and 33 million user phone numbers were stolen - eviltoast
  • Passerby6497@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 months ago

    I wonder if this an example of a trade-off between convenience and security.

    I genuinely wonder if it’s advisable to not use MFA at all if the factors will not be separated. Or, perhaps, the best security solution is the one you’ll actually use

    Your first and last statements are correct. Using your password manager as your MFA is a trade off with security and convenience, but that added convenience helps make it more usable so you actually use it. Anything is a trade up for most peoples’ awful password hygiene, so the trade off is worth it in my opinion.

    Regarding the advisability of combining password and MFA into one platform: while you are lowering the overall security of your accounts, if you secure the main account with a long/strong password and a hardware security key, I would say that’s still more secure than not having 2FA enabled or not using secure passwords.