47 karma · joined May 21, 2018
Generally, a one-time password is an additional security measure that prevents someone from going to a website and simply using obtained credentials (eg from a leak) or brute-forcing them. An attacker needs the second factor.
If you store your 2FA secret alongside your password in a password manager, you still gain protection from these attacks. And it's very convenient. However, you also increase your attack surface: if they break into your password manager, your done.
If your threat model allows it (mine does), this is still very secure and also very convenient.
The second one is more difficult to evaluate. If you use the above mentioned "secret chat" feature, Telegram employs their own closed-source encryption scheme. That's usually an indicator to be cautious from the get-go. Since it's closed source, it can't really be trusted.
See [Wikipedia](https://en.wikipedia.org/wiki/Telegram_(software)#Security) for a timeline in regards to the security.
There are other apps, that are even worse. Allowing something to open in a new tab/window but identifying that there are multiple windows open and just disabling all but the main window...
I don't understand developers that do this. I always felt that multiple tabs is a strength of the web. They worsen it somehow.
Man I hate the new web.
One thing I read somewhere and previously never thought about: if you are _really_ about security, you should use a password manager and should enable 2FA.
But: you should not use one program for both (1Password offers this), because you are creating a single point of failure.
However, picking the correct hardware and figuring out the necessary basics is a challenge in itself. You need patience and technical knowledge. So it is far from going into the store and purchasing an iMac. That is certain. But it is not as dark as you are putting it, IMHO.