• x1gma@lemmy.world
    link
    fedilink
    arrow-up
    3
    arrow-down
    4
    ·
    edit-2
    29 days ago

    Yes, in your head, and in your second factor, if possible, keeping derived secrets always encrypted at rest, decrypting at the latest possible moment and not storing (decrypted) secrets in-memory for longer than absolutely necessary at use.