Nevertheless I chose my Yubikey instead.

you are viewing a single comment's thread
view the rest of the comments
[–] 36 points 2 years ago (6 children)

I do this. I want to point out it is absolutely TERRIBLE for security. It's turning 2 factor back into 1 factor authentication.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 15 points 2 years ago

    I would argue its more like a 1.5 factor. Not secure when your bitwarden gets compromised. But more security for stolen, leaked, phised passwords.

    I currently have 60 OTPs in Bitwarden, I probably would not have activated 2FA on so many sites without BW.

  • source
  • parent
  • [–] 2 points 2 years ago (3 children)

    yeah, while I understand that, it's not every time I have both my phone and computer together at the same time

    using a standalone OTP on either one of them would make the opposite a pain in the ass to use

    I take a lot of precautions with my main vault password, even got a biometric reader so I don't have to type the password that much

  • source
  • parent
  • hideshow 3 child comments
  • [–] 2 points 2 years ago (2 children)

    You're absolutely right. It's all about your threat model, how much convenience you're willing to lose and what not.
    I absolutely should do more to minimize potential risk, but it's really so convenient to just.... Have it all in 1 place...

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago (1 child)

    Something that I do to make sure I’m more protected is that I don’t put the two-factor for my main email accounts into Bitwarden.

  • source
  • parent
  • hideshow 1 child comment