this post was submitted on 10 Oct 2024
224 points (99.6% liked)
196
17053 readers
864 users here now
Be sure to follow the rule before you head out.
Rule: You must post before you leave.
If you have any questions, feel free to contact us on our matrix channel.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Next time save the secret string on a password manager like KeePassXC to syncronize the files to your PC
Yeah! Defeat the dragon of phone 2fa by putting all your secondary passwords on the cloud, synced to your computer! That'll show em :D
KeePassXC is offline, it uses local storage
If you sync it it isn't offline by definition. Might not have to be on google/one drive, but has to be acessible over some network (probably even the internet).
Syncing can be through a peer to peer protocol such as sync thing where both devices would need to know each other's Device IDs, and the Device IDs are basically just SHA256 hashes of locally generated keys.
Or if the user uses a program to sync over the local network or over USB it's not necessarily online
You mentioned cloud, and that's really not needed. If you need sync, you can use a P2P service like Syncthing, and while your data is transmitted over the Internet, any threat actor would need to
a) identify your device IDs and intercept your traffic b) crack the encryption of the network traffic c) crack your password d) (if you used a key file, crack that as well)
If that is not safe enough for your threat profile, sure, don't use a password manager, but at that point you got bigger problems