2 ms·
Whilst hardware keys are clearly better, I appreciate how storing TOTP keys on bitwarden also largely mitigates this kind of phishing. Bitwarden also checks the
by gingerlime 4y ago
Whilst hardware keys are clearly better, I appreciate how storing TOTP keys on bitwarden also largely mitigates this kind of phishing. Bitwarden also checks the domain name, so if you don’t see the auto-login option (with or without 2FA), you should be concerned and not proceed. I know that storing the TOTP keys in Bitwarden kinda reduces the second factor to one factor. But practically I would argue that this kind of phishing is a bigger risk than someone hacking Bitwarden itself. For small orgs without security teams and resources, promoting password manager usage and including TOTP keys is a smart move.
- tialaramex 4y agoIn theory this seems like it could be enough, but in practice there will be sites where they change the DNS name and so you must override, and because that feature exists some fraction of phishing targets will override. The crucial trick in WebAuthn is there isn't an override button. There is no "fall for the phishing scam" button, so there's no way to push it.
- barbazoo 4y agoSame with 1Password