I've been using Authy before Tofu and it can be configured to require PIN or biometrics to be able to interact with the app. I think this enhances the security since there are moments when the phone is unlocked but not in the hands of the righteous owner(tm). I can name 3 other apps (mostly banking / finance) that use this technique, so seems like an established practice.
I've been using Authy before Tofu and it can be configured to require PIN or biometrics to be able to interact with the app. I think this enhances the security since there are moments when the phone is unlocked but not in the hands of the righteous owner(tm). I can name 3 other apps (mostly banking / finance) that use this technique, so seems like an established practice.