5 ms·
Nobody forces you to use sms for 2fa. I'm not even sure vaultwarden supports SMS. I use https://getaegis.app https://getaegis.app with usual 2FA TOTP, also prot
by rlex 5y ago
Nobody forces you to use sms for 2fa. I'm not even sure vaultwarden supports SMS. I use https://getaegis.app https://getaegis.app with usual 2FA TOTP, also protected by password. So for someone to gain access to your vault will need:
* access to your server with bitwarden/vaultwarden (this one is tricky, someone might inject something in webui JS if it's open to public internet, so keeping it VPNed might be good idea indeed)
* access to your master password
* access to your mobile device / totp storage and password for it
I'd say it's pretty safe from random hackers, but if someone is dead set on getting your data, well https://xkcd.com/538/ https://xkcd.com/538/