Go with the time and accept that 2FA everywhere is good and the norm. As someone else mentioned: Browser-integrated password managers can autofill 2FA for you, meaning there's no extra hassle needing to lookup, copy, paste & confirm an extra step.
Go with the time and accept that 2FA everywhere is good and the norm. As someone else mentioned: Browser-integrated password managers can autofill 2FA for you, meaning there's no extra hassle needing to lookup, copy, paste & confirm an extra step.
Meaning that it defeats the entire point of 2FA. 2FA used in this way is only security theater.
If someone compromised your password store, then yeah it's all over. But if the compromise happens elsewhere, it can be a useful layer to the security onion.
But 2FA still helps if a single password was leaked/bruteforced/phished, and afaict most password managers in autofill mode recognize the browser url, so it’s quite phising safe (2nd factor won’t be autofilled on wrong website)
Security is not binary, and 2fa via password manager is still much better than no 2fa; it’s not pointless.
Why? It depends on your scenario. If it is “attacker gets hold of my wallet” then yes, you’re screwed.
But 2FA still helps if a single password was leaked/bruteforced/phished, and afaict most password managers in autofill mode recognize the browser url, so it’s quite phishing safe (2nd factor won’t be autofilled on wrong website)
Security is not binary, and 2fa via password manager is still much better than no 2fa; it’s not pointless.