mooltipass / minible

Github repository containing the firmwares running on the Mooltipass Mini BLE
GNU General Public License v3.0
97 stars 21 forks source link

TOTP Password #332

Open d3t4ash opened 2 years ago

d3t4ash commented 2 years ago

Is it possible to add new main menu for TOTP Password list in the minible?

It is very handy if we can access the TOTP in the main menu of minible. Please also consider to make this menu in the Moolticute for easy setting (using QR Code scan or type the secret code directly) and displaying this TOTP in the apps.

awilkins commented 1 year ago

Counterpoint ; if you're using your BLE as part of an MFA solution, putting your TOTP key in the same device as your password turns it into OFA.

Sazoji commented 10 months ago

Counterpoint ; if you're using your BLE as part of an MFA solution, putting your TOTP key in the same device as your password turns it into OFA.

The device's master pass is already MFA; Key, pin, and the correct database (not just any device unless loading a backup) are all required to be together at that moment in time to unlock. Having an additional hw key or a phone for auth is not adding an appreciable increase in security, especially if they increase the attack surfaces like a phone can.