{
  "$type": "site.standard.document",
  "bskyPostRef": {
    "cid": "bafyreigdnbugkjhd4v4ucaogplzqiscnhaqxnxiwpc2abhurtw2ytdxld4",
    "uri": "at://did:plc:haakkg7y3xdghcdmprxeexso/app.bsky.feed.post/3mlohwm4tqjx2"
  },
  "path": "/t/totp-apps-vs-windows-hello-passkeys-for-2fa/37842#post_4",
  "publishedAt": "2026-05-12T17:49:09.000Z",
  "site": "https://discuss.privacyguides.net",
  "tags": [
    "Privacy Guides",
    "Password Managers - Introduction to Passwords - Privacy Guides"
  ],
  "textContent": "Windows Hello supports device-bound passkeys so you can use your Windows PIN or biometrics as 2FA/logins for websites. If I understand correctly, Microsoft does not have access to them, and you are unable to store them on the cloud even if you want to.\n\nAlso, isn’t using a password manager to store passkeys functionally the same as using password managers for TOTP? One of the very first articles in Privacy Guides warns against that:\n\nPrivacy Guides\n\n### Password Managers - Introduction to Passwords - Privacy Guides\n\nPasswords are an essential part of our everyday digital lives. We use them to protect our accounts, our devices, and our secrets. Despite often being the only thing between us and an adversary who's after our private information, not a lot of thought...\n\n”**Don’t place your passwords and TOTP tokens inside the same password manager**\n\nWhen using TOTP codes as multifactor authentication, the best security practice is to keep your TOTP codes in a separate app.\n\nStoring your TOTP tokens in the same place as your passwords, while convenient, reduces the accounts to a single factor in the event that an adversary gains access to your password manager.\n\nFurthermore, we do not recommend storing single-use recovery codes in your password manager. Those should be stored separately such as in an encrypted container on an offline storage device.”\n\nGetting a hardware key seems like maybe overkill to me, I’m not sure. What do you think?",
  "title": "TOTP Apps vs Windows Hello Passkeys for 2FA"
}