Remix.run Logo
thrownaway561 2 days ago

Honestly.... This is why I have everything in Bitwarden. All 2FA runs through it so even if my phone got stolen, I could still access everything. I honestly don't understand why more people don't pay the $10 a year and just use Bitwarden.

phainopepla2 2 days ago | parent | next [-]

Having your passwords and 2FA with the same provider carries some risk. If someone can access your Bitwarden account they will have full access to all your accounts.

ectoloph 2 days ago | parent | prev | next [-]

I always feel conflicted with this.

Using my password manager to store 2FA codes is convenient, but it adds a layer of indirection if they are elsewhere.

But if you've compromised my password manager, you almost certainly have enough access to my machines to get to the alternatives.

vel0city 2 days ago | parent | prev | next [-]

What's your plan when you lose access to Bitwarden?

What happens when your Bitwarden gets compromised?

patshead 2 days ago | parent | prev [-]

> All 2FA runs through it

I hope that isn't true, because I sure can't think of a good way to use Bitwarden's TOTP as 2FA for Bitwarden! :)

vablings 2 days ago | parent [-]

FIDO2 USB Security key -> Bitwarden (With master password) -> Every other 2FA method

I have 3 FIDO2 USB Security keys, One I carry with my persons at all times, one that stays with my main machine at all times and an offsite backup that is sitting in a friend's server, if my house burns down, I can either physically collect the key or use USB-IP to authenticate back into bitwarden and enroll a new key. (Actually all 3 are at home right now but that's ok)

My phone is logged into Bitwarden so even then I can recover my passwords and data in case of a serious incident immediately.

Even if both my house and my friend's house burn down at the same time, I can still recover my data from my phone unless my phone is left in the house, all of which to say I still have the recovery phrase written down in a box somewhere in a different country