Just takes a brute force or 0 day vulnerability to get master password access, them they have everything.
Something that seems secure never is online, like the 2017 Intel managetment vulnerability where remote attackers could access your computer by sending a null password, and access your keyboard and camera etc
BCsven@lemmy.ca 5 days ago
Use a yubikey hardware device, only the person with the hardware in hand and password can unlock your accounts
MDCCCLV@lemmy.ca 5 days ago
You don’t want that as the only option though, because you can definitely lose that and it’s not incredibly hard to break.
BCsven@lemmy.ca 5 days ago
The solution to that is you purchase a backup key and enroll both when presented with the QR image for new OTP links, or add a secondary FIDO key on some accounts. Then you store the other one in a fireproof box.
Or you use a cryptographic key and print it out using shard tool. The shard tool lets you specify how many splits and how many requires for a tebuild. It prints out the shards and you distribute to safe places or people. They are useless by themselves but if you scan in the requires amount of pieces the tool will rebuild your cryptographic key