3 ms·
I use Bitwarden for passwords, so... i dont really like that mucho having 2Fa there too... It losses the porpoise of the 2fa.
by neoecos 2y ago
I use Bitwarden for passwords, so... i dont really like that mucho having 2Fa there too... It losses the porpoise of the 2fa.
- rpgbr 2y agoNot really? Even in the same basket, having TOTP and passwords on iCloud mitigates a lot of scenarios, such as leaked passwords. Depending on your threat model, this solution is ok — way better than no 2FA at all or SMS. 1Password has a nice article regarding this point: https://blog.1password.com/1password-2fa-passwords-codes-together/ https://blog.1password.com/1password-2fa-passwords-codes-tog...
- ancientworldnow 2y agoBitwarden has a separate 2fa app so your totp codes aren't in the same password vault (though you can do that, but shouldn't).
- aryonoco 2y agoWhy shouldn't you? I use a Yubikey as the 2FA for my bitwatden, then store all the TOTP codes with the passwords in the same vault. Quite convenient, and also adheres to the principles of MFA