Comment by schrodinger

1 day ago

That’s a good point.

Maybe a good compromise is to use 1pw for most TOTP but keep your gmail / iCloud and a few others in an iPhone only app?

Gmail is what scares me the most. It’s basically keys to the kingdom.

> Gmail

We might all do well to remind F&F to print out account recovery codes, and then put some thought into where they'll be safe.

I settled on that after trying to be extra careful with TOTP. Now my split is 95% of passwords, TOTP codes and passkeys in 1Password, 5% (really important stuff like email) in an offline KeePass DB + passkeys on Yubikeys.