> Browser-integrated password managers can autofill 2FA for you
Meaning that it defeats the entire point of 2FA. 2FA used in this way is only security theater.
Meaning that it defeats the entire point of 2FA. 2FA used in this way is only security theater.
If someone compromised your password store, then yeah it's all over. But if the compromise happens elsewhere, it can be a useful layer to the security onion.
But 2FA still helps if a single password was leaked/bruteforced/phished, and afaict most password managers in autofill mode recognize the browser url, so it’s quite phising safe (2nd factor won’t be autofilled on wrong website)
Security is not binary, and 2fa via password manager is still much better than no 2fa; it’s not pointless.