4 ms·
>I no longer have to worry about not having my phone on me, or even having to take it out of my pocket. I mean, I appreciate the convenience but can't help fee
by jabbany 3y ago
>I no longer have to worry about not having my phone on me, or even having to take it out of my pocket.
I mean, I appreciate the convenience but can't help feel like this is cheating...
The whole point of 2fa was to verify you had the 2fa device and this basically defeats that.
- JohnFen 3y ago"Cheating" is an odd way to put it. Everyone has their own security risk profile. If someone decides that effective 2FA isn't worth it considering their own profile, that's legitimate. It's not "cheating", it's finding ways to work with the system you have in the way that you deem best for you.
- andrewaylett 3y agoA 2fa device, perhaps? Access to Bitwarden requires 2fa, and confers on the device I logged into the ability to 2fa for other purposes. I don't leave Bitwarden unlocked for more than a few seconds, so the two factors are "having a device on which I've logged into Bitwarden already" and either "being able to satisfy a biometric sensor" or "knowing my passphrase". I do also have the ability to bootstrap Bitwarden access on a new device without an existing device -- the two factors then being "knowing my passphrase" and "having my security key".