Should 2FA codes live in your password manager?

Many password managers – Apple Passwords, 1Password, Bitwarden – can also generate two-factor codes. It’s convenient. But it puts both factors in the same place.

What two-factor authentication is for

Two-factor authentication asks for two things: something you know (your password) and something you have (the device that generates the code). The idea is that an attacker needs both. A leaked password alone isn’t enough, and neither is a stolen code.

One vault, two factors

If the password manager also holds the 2FA secret, both factors come from the same place. Whoever gets into that vault – through a weak master password, malware on your Mac, a phishing page for the vault itself or a breach at the provider – gets the password and the code generator in one go. The second factor then no longer protects against the thing it was made for.

Most of the time nothing goes wrong. But two-factor authentication is exactly for the time something does.

Keeping them apart

With a separate authenticator, the password stays in your password manager and the second factor lives somewhere else:

But isn’t that less convenient?

It doesn’t have to be. Press ⌥⌘A in any app, type a few letters of the service and press Return – the code is on the clipboard. In Safari and other apps that use the system’s AutoFill, the code can also be offered right in the login form. That’s about as fast as a password manager, with the second factor still kept apart.

When a password manager is fine

Codes in a password manager are still far better than no two-factor authentication or codes by text message. With a strong, unique master password and unlocking by Touch ID, the risk is small. But if you want the two factors to really be two, keep them in two places.

In short

← All articles