13 ms·
Bitwarden Authenticator
- sepositus 2y ago> In this initial release, your data will be backed up through the mobile operating system's backup services. Please make sure your device is turned on and configured for backups. Bitwarden Authenticator data is included in the OS backups and will be restored with them. At least it's not defaulting to their own cloud service backend. This has always been my problem with these types of apps. Although, I'm not sure I fully understand the above description. I'm guessing if you have an iPhone with iCloud backup enabled, it means data is backed up to iCloud.
- hackmiester 2y agoOr if you are using "iTunes backups" it will store them in there as well.
- stwrzn 2y ago> New features on the roadmap include import, syncing to Bitwarden accounts, push-based 2FA, and account recovery. When syncing is added it would actually be something to consider.
- lxgr 2y ago> [...] syncing to Bitwarden accounts [...] In that case, what would be the advantage over just using Bitwarden's native TOTP support?
- fn-mote 2y agoAre your cloud backups encrypted? Yes, but the key is backed up too. [1] The regular complaints here about iMessage not having good E2EE is a specific exception written into the security policy. Corrections welcome. [1]: https://support.apple.com/guide/security/security-of-icloud-backup-sec2c21e7f49/web https://support.apple.com/guide/security/security-of-icloud-...
- janalsncm 2y agoIt really depends what your threat model is. If you are concerned about government intervention a TOTP isn’t going to stop them.
- coder543 2y agohttps://support.apple.com/en-us/102651 https://support.apple.com/en-us/102651 I think this is the better link. Advanced Data Protection is end to end encrypted, without the key being backed up to Apple’s servers.
- bramhaag 2y agoThis of course only helps if ADP is available in your country and you've turned it on.
- procaryote 2y agoKinda worrying that it doesn't mention anything about how that is secured. Google Authenticator had the fun idea to opt people into unencrypted (beyond whatever regular google drive files have) cloud backup of 2fa secrets, and it's been exploited in the ways you'd expect.
- izacus 2y agoBoth mobile operating systems use e2e encryption for the backups.
- Tepix 2y agoNot in the UK for icloud
- stavros 2y agoAndroid doesn't encrypt everything, and the details of what it does and doesn't encrypt are so fiddly that I don't feel confident enough to enable cloud backups.
- sneak 2y agoNo, iOS backups are not e2ee unless you go and opt-in to it, which approximately 0% have done.
- wongarsu 2y agoOn my Android, what's the upside of using this instead of Google Authenticator if they both back up to the same place? If they used their own cloud backend I would be a lot more interested. They could even offer to store it in their cloud end-to-end encrypted (making it my responsibility to keep the password safe). That would give me similar exposure as their password manager, which I'm already using.
- NewJazz 2y agoHow would this work on a degoogled android? I just use freeotp+ and have backup codes in case I lose the device.
- ThePowerOfFuet 2y agoUse Bitwarden with a Pro subscription ($10/year).
- stwrzn 2y agoOr host self-host the server
- rowlandc 2y agoVault warden is much easier to self host and does all the same things, without the need for a premium subscription too.
- cyberge99 2y agoWhy are people so adverse to having premium accounts if it’s reasonably priced and provides value?
- elashri 2y agoYou can pay customary $10 per year to bitwarden to support and still selfhost valultwarden. Some people want to have control and don't want to have to deal with VC money getting in the way (1password was a hard learnt lesson). Also vaultwarden seems lot cleaner and easier to install and manage than official bitwarden server. And you still rely on their clients.
- Uvix 2y agoVaultwarden used to be a lot easier to install, but the official server also has a single-container option now: https://bitwarden.com/help/install-and-deploy-unified-beta/ https://bitwarden.com/help/install-and-deploy-unified-beta/ It's technically in public beta still, but I've been using it for a year and a half without any issues.
- makeitdouble 2y agoIs it standard for Bitwarden to have absolutely no mention of a any plan to also build a PC app ? I can't find any.
- sigmoid10 2y agoBitwarden does come with an app for every major operating system. Or do you mean this authenticator app? It kind of goes against the idea to have this anywhere but your phone.
- serial_dev 2y agoI don’t see why an authenticator app could not be used from desktop or web.
- sigmoid10 2y agoIf you store your second factor on the same device where you login, there's really no need for an app (or a second factor for that matter), because if your device is compromised, you're screwed anyway. You might as well store a list of one time auth passwords on a piece of paper that you keep near your PC. In fact that way someone would have to compromise you physically and digitally, which may be more difficult. If you keep the paper on your person at all times, it will actually be pretty secure. If you use some encryption scheme for the text on top of that, you're already pretty much there. But that's complex, so people came up with hardware keys that you always keep on your person and that are not used for anything else. They are kind of the ultimate thing to deploy on scale, but still a lot of hassle for users. The next best thing is using an app on your phone. It's considerably more dangerous, but still much better than storing everything on your computer.
- serial_dev 2y agoI could have two computers, and I could also login to an app on my phone. There are valid reasons for a desktop authenticator app.
- stavros 2y agoI'm confused, doesn't BitWarden already include this functionality? I've been using it for years, have they split it out into a separate app? I tend to use Aegis for the two services' TOTP codes that I don't put into BitWarden.
- deleted 2y ago[deleted]
- twoparachute45 2y agoThe built-in TOTP in Bitwarden password manager is only available to premium Bitwarden subscribers, requires you to have a Bitwarden account, and stores your TOTP codes in Bitwarden's servers. This standalone app is available for free, can be used without an account, and the TOTP codes are only stored locally (or through your phone's native backup system). Some people dislike the idea of storing TOTP codes in the same location as passwords, so it seems this helps provide those people with that separation, while still using Bitwarden products (which tbh is cool with me - a lot of the other TOTP apps on the appstores suck).
- stavros 2y agoThat makes sense, thank you!
- elashri 2y ago> Some people dislike the idea of storing TOTP codes in the same location as passwords, And many organizations/companies have policy against that although I don't know how can anyone enforce that.
- nyolfen 2y ago> The built-in TOTP in Bitwarden password manager is only available to premium Bitwarden subscribers, requires you to have a Bitwarden account, and stores your TOTP codes in Bitwarden's servers. if you selfhost (eg with vaultwarden) you get all the pay features for free
- 2y ago
- deleted 2y ago[deleted]
- layer8 2y agoIt doesn’t support syncing between devices. An alternative is Ente Auth: https://news.ycombinator.com/item?id=40883839 https://news.ycombinator.com/item?id=40883839 Edit: Since there seems to be some confusion, this submission is about Bitwarden Authenticator, a free mobile app for TOTP, not about the Bitwarden password manager, which does support syncing, and which in the paid Premium plan also includes an authenticator.
- satvikpendem 2y agoI use this, it works great for when you're on a laptop and can't be bothered to pull out your phone to enter the 2FA code (because it works cross-platform on web, desktop, and mobile, all syncing together). Yes, technically this is a corruption of the principles of why you'd need 2FA in the first place, as the second factor is obviated when everything is on one device, but I find the risk acceptable, no one is going to hack into my laptop at home, and if they do, I have bigger things to worry about than 2FA.
- Marsymars 2y ago> Yes, technically this is a corruption of the principles of why you'd need 2FA in the first place I understand what you’re saying here, but then having a password manager and a 2FA app on the same phone is the exact same corruption. If your threat model involves “don’t have your 2FA codes on your desktop”, it must also include “don’t have your passwords on your phone”.
- satvikpendem 2y agoThat's probably true. For what it's worth I don't save passwords on my phone either.
- magixx 2y agoCan you elaborate? The android app, browser extension, and desktop app all keep in sync for me.
- 2y ago
- samstave 2y agono. Zero trust, and that it slides auth horizontally to other untrusted flows... Like literally walk an LLM through my data path?
- yoyohello13 2y agoSo I’ve been a happy Bitwarden subscriber since about 2020. I originally picked it because it seemed like a good compromise between open source options like keepassxc and something less trustworthy like one password. I haven’t really be paying much attention to Bitwarden lately, but I’ve heard they’ve taken vc/got bought out or something. So for those more in the know, is it time to start migrating? Or does Bitwarden still seem like it’s on a good path?
- aetherspawn 2y agoWhy do you say 1Password isn’t trustworthy? We’ve been using 1P close to a decade and they’ve managed to not leak our passwords that whole time, unlike many other cloud password managers who have had breaches.
- yoyohello13 2y agoSorry, I didn’t mean to specifically call out 1password. I should have said “closed source” not “untrustworthy”. Last time I looked at password managers Bitwarden and keepass were the only real oss solutions. And Bitwarden had better qualify of life features.
- marcosscriven 2y agoHow does this compare to Authy? I use Bitwarden and have been very frustrated with their UI changes.
- kwanbix 2y agoYeah, their UI is getting worst. Now some genius decided that the default if you touch a login, is to edit, not to fill the form.
- tecleandor 2y agoYeah! I hated that! Thankfully I found that you can change that behavior in a preference.
- mvdtnz 2y agoAnd you need to change that preference on every single device, it will not change your default. And they hide this option in a weird place away from all of the other Appearance options. I'm not one to complain about UI changes but some of their recent decisions are baffling beyond belief.
- kwanbix 2y agoyeah, as a PM and former dev I always wonder who decides this type of things.
- deleted 2y ago[deleted]
- locusofself 2y agoI hate this too
- dankwizard 2y agoDo a few searches of "Authy" and you'll be switching sooner rather than later. Absolutely awful app.
- mdevere 2y agoBig fan of Bitwarden, albeit you are putting a single point of failure on all of your secure info. I'd love to know what others do to maximise both convenience and security. For two-factor authentication, I wouldn't use the same service for both layers. Seems daft to use Bitwarden as both the password keeper and the TOTP provider. Not sure if that's a cryptographically coherent view, but hey.
- tomasff 2y agoBitwarden Authenticator is a separate service. Even if you don't use bitwarden you can use this apparently
- wongarsu 2y agoBut if somebody compromised their internal infrastructure they could push out malicious updates to both the Authenticator and the clients of the password manager (most likely the browser extension), compromising both security factors at once
- cwalv 2y ago> albeit you are putting a single point of failure on all of your secure info. Depends on what failure mode you're talking about. If you mean "I won't be able to access things when their service is down", that's not entirely accurate, because the database is synced to clients, so you just can't connect a new client or add/update entries, but existing entries are accessible. If you mean "everything will be compromised if their service is hacked", that's not quite accurate either, because the encryption key to the database isn't stored on their servers (things are only ever decrypted on the client). If you mean "any compromise is all/nothing", this is kindof true, but can be mitigated by keeping separate vaults, so that your most sensitive items are not kept with the ones you need routinely. Or maybe you're thinking of some other failure mode ...
- josh-sematic 2y agoIn terms of a compromise being “all or nothing,” most secure accounts should have a password (which you can manage in BitWarden) AND a second factor (ideally not tied to your phone; ex: a YubiKey). That way even in the nightmare scenario that someone gets into your password manager there’s extra legwork they’d need to do to ruin you.
- ViVr 2y agoI'd like to see them add support for including attachments in your Bitwarden exports before i go putting any more critical data into their ecosytem. It has been a feature request for close to 6 years now: https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835 https://community.bitwarden.com/t/allow-attachments-to-be-ex...
- jackhalford 2y agoPersonally I just backup the underlying filesystem (i.e /data) that vaultwarden uses. Edit: I realize you are probably using bitwarden directly, in which case don’t you trust them to safeguard your data? ps: if it’s just ssh keys, just store them as key value pairs? I haven’t kept ssh keys for a long time thanks to tailscale ssh…
- ViVr 2y ago> I realize you are probably using bitwarden directly, in which case don’t you trust them to safeguard your data? Yes i use bitwarden directly, no self hosting. I do trust them keep my data safe (although i also trusted LastPass at some point, big mistake) but why not also keep a local copy, just in case. The type of data you store in bitwarden is worth the hassle and if Bitwarden Inc. ever gets into big trouble suddenly you'll be glad to have the backup.
- jackhalford 2y agoIf the data worth the hassle to backup, isn’t it worth the hassle to self host? Especially if you were part of the lastpass breach
- jackhalford 2y agoFunny this pops up today, I’ve finished migrating form KeepassXC to a self hosted vaultwarden, the official bitwarden apps and briwser extension are super well made, so good so far with the switch.
- Paul-Craft 2y agoOkay. So? HOTP and TOPT are so trivial to implement, you can even use a C64[0] as your 2FA device. Here's my anti-FAQ[1] to their FAQ: --- ### TOPT ANTI-FAQ 1. Want a guide to implementing time-based passwords in your app? Here you go: https://www.freecodecamp.org/news/how-time-based-one-time-passwords-work-and-why-you-should-use-them-in-your-app-fdd2b9ed43c3/ https://www.freecodecamp.org/news/how-time-based-one-time-pa... 2. What was that? You want to do it in Typescript? Okay, here you go: https://www.npmjs.com/search?q=totp https://www.npmjs.com/search?q=totp 3. Want to do it in Python? Unfortunately, you only have 275 choices: https://pypi.org/search/?q=totp&o=-created https://pypi.org/search/?q=totp&o=-created 4. How about on an Arduino? https://github.com/lucadentella/TOTP-Arduino https://github.com/lucadentella/TOTP-Arduino 5. Fuck it, we'll do it ~~live~~ in Emacs!https://www.masteringemacs.org/article/securely-generating-totp-tokens-emacs https://www.masteringemacs.org/article/securely-generating-t... Y'all get the point by now, I'm sure. --- [0]: https://www.gadgetany.com/news/now-the-commodore-64-is-a-two-factor-authentication-device/ https://www.gadgetany.com/news/now-the-commodore-64-is-a-two... [1]: "Anti"-FAQ, because I'd like to discourage people from wasting brain cycles on thinking that a time-based authenticator app is something worth announcing.
- haswell 2y agoI’ve been using the “OTP Auth” app by Roland Moers since hearing about it on Steve Gibson’s Security Now podcast. Extremely happy with it.
- denkmoon 2y agoDoesn't appear to have any way of exporting 2FA tokens? I _very narrowly_ dodged being locked in to authy by having tokens in there that couldn't be exported, and authy is a steaming pile of... Never again will I be foolish enough to not maintain ownership of the actual 2fa tokens my codes are generated from.
- poglet 2y agoAs an Authy user who is trying to escape do you have a 2fa recommendation>
- Fnoord 2y agoAegis. It is FOSS.
- silverwind 2y agoAegis is great, but not available for IOS.
- discardedrefuse 2y agoNot OP, but I escaped Authy over a year ago and I've been happy with 2FAS on Android. Aegis is also very good. 2FAS has backup to Google Drive. Aegis does Android Cloud Backup. Aegis is available on FDroid. IIRC I chose 2FAS for purely aesthetic reasons, but I could've easily gone with Aegis and been happy too. Speaking of escaping Authy, good luck with that. I had to use their desktop app and api to pull my data. I read in another comment that they've recently closed that api. So, you might be stuck migrating each account manually. That bullshit alone is worth the trouble of moving.
- denkmoon 2y agoYep, exactly this. I, purely coincidentally, did this procedure of hacking up their desktop client to export my tokens 3 weeks before they turned off the API the desktop client uses. "by the skin of my teeth" as it were. I also use 2FAS. It has token export.
- deleted 2y ago[deleted]
- Ecko123 2y ago[dead]
- yumraj 2y agoI had exported my tokens out of Authy when they had killed the desktop version, and imported into KeypassXC. I find keypassxc which I use for managing passwords and now TOTP to be the best option for me. I still use Authy on mobile but having an offline backup is great.
- ripped_britches 2y agoI have used Bitwarden for a few years happily, but have been really annoyed at the UI changes in the chrome extension Not only does it unnecessarily jar me out of my memorized places to click, but it also just takes 2 clicks to copy a password instead of 1. Seems like a small deal but it is genuinely a bad UI.
- WhipeeDip 2y agoIf you go to Settings -> Appearance and enable show quick actions, you can reenable the 1 click copy password again. Enabling compact mode and disabling animations also helps a lot.
- Beaving 2y agoYes, but then you have to click the little "Fill" button. And if you enable "Click items to enable autofill on Vault view", you have to Rightclick -> View to edit stuff.
- woleium 2y agocmd+shift+l, or ctrl+shift+l (lower case L)should just autofill even the totp fields (notably and annoyingly not totp for microsoft auth though)
- HypnoticOcelot 2y agoIf you enable Autofill > Copy TOTP Automatically, when you use that keybind it'll copy the TOTP to your clipboard so that you can paste it in when prompted for it
- landtuna 2y agoI think you can fix this with the setting "Click items to autofill on Vault view".
- RockRobotRock 2y agohttps://bitwarden.com/blog/bringing-intuitive-workflows-and-visual-updates-to-the-bitwarden-browser/#tips-for-long-time-bitwarden-users https://bitwarden.com/blog/bringing-intuitive-workflows-and-...
- jz10 2y agoI just literally spent a week transferring all my authy keys to Bitwarden's somewhat hidden OTP generator feature. nice to see they finally made a standalone app. Now I'm gonna find out if both are integrated..... (I really hope so)
- bramhaag 2y agoI have been using Aegis [1], a FOSS (GPLv3) TOTP authenticator app, for the past years. It supports: - Local encrypted backups. You can sync these to where ever you like on your own terms. I automated uploading mine to my local NextCloud instance. - Importing from other authenticator apps, so you can easily migrate. - Exporting entries so that you are not vendor locked (cough cough Authy). - Customization. - No mandatory cloud bs, LLM integration, tracking, ... [1] https://github.com/beemdevelopment/Aegis https://github.com/beemdevelopment/Aegis
- hresvelgr 2y agoFYI Bitwarden is self-hostable and AGPLv3.
- layer8 2y agoAegis is Android-only though. A cross-platform (Android/iOS/Linux/Mac/Windows), open-source (AGPLv3), self-hostable (Docker image) alternative (with migrations, E2EE backups/syncing, and JSON export as well) is Ente Auth: https://news.ycombinator.com/item?id=40883839 https://news.ycombinator.com/item?id=40883839
- bootcat 2y agowhy can't this be in the same app,
- hedora 2y agoThe “An Error Occurred” database corruptions last year convinced me I can’t trust bitwarden any more. Any suggestions for something I can host at home? It needs mac, linux and ios clients and (unlike bitwarden) must gracefully handle the server being unavailable.
- bramhaag 2y agoVaultwarden [1] if you want to keep using the Bitwarden clients but with a different, self-hosted backend. You can also use KeePassXC and self-hosted file service to sync your database between devices [2]. KeePassXC has a merge feature in case one of your local databases diverges, so the server being unavailable is not an issue. [1] https://github.com/dani-garcia/vaultwarden https://github.com/dani-garcia/vaultwarden [2] https://keepassxc.org/docs/#faq-cloudsync https://keepassxc.org/docs/#faq-cloudsync
- hedora 2y agoI’m using vaultwarden, and am happy with it. The official client is the problem. Given the catastrophic outcomes associated with corruption of the DB, I can’t imagine trusting the keepassxc approach. How can they possibly handle concurrent updates to the password database correctly across that range of cloud filesystem products? Each has different semantics. Does someone fuzz test the whole stack, at least? For which services?
- bramhaag 2y agoI can only speak for my own setup: KeePassXC on multiple devices with a local NextCloud instance for syncing my database. First and foremost, automate backing up your database. NextCloud also supports versioned files, so if something does go wrong, you can roll-back to a working DB as a last resort. A good syncing application will not upload files that are currently opened in write mode. This way you cannot upload files mid-write, preventing uploading corrupted DBs. This of course assumes that both KeePassXC and NextCloud are perfect, but even if something breaks there you have your automated backups and previous versions of the database file. I should note that this has never happened to me, but if it were to happen I am safe. In case you have diverging databases (e.g. server is offline and you add a new account on device 1 and a different account on device 2), NextCloud will create a conflict file which you can merge from the KeePassXC client to resolve the issue. No accounts are lost but it is an additional manual step to get all your changes back into the "main" DB.
- itsthecourier 2y agoI was a LastPass client then they got hacked and I moved to bitwarden. feel better with their app integration and it feels good. yet I wouldn't use their 2fa app, just because if they get hacked at some point I don't want passwords and 2FA stored with the same company doing great with authy in that front
- beebaween 2y agoDo I still have to pay extra to use a yubikey?
- Lord_Zero 2y agoAre we all off the 2FAs train now?
- kyriakos 2y agoAt some point Microsoft authenticator decided that 2fa from a smartwatch shouldn't work (that happened when they introduced the 2 digit number verification which could still work fine on a watch). I have yet to find a replacement for that feature. If anyone figure it out please let me know!
- sneak 2y agoTOTP is bad. TOTP is phishable. Stop using or promoting TOTP. We have modern authentication called WebAuthn, supported by Bitwarden proper as well as physical security keys and iOS’s native password manager. Use it.
- Sharparam 2y agoTOTP is still the MFA option that is supported by most services. WebAuthN is of course better, but it's still a minority that supports it.
- linsomniac 2y agoI agree that webauthn is a better choice than TOTP, but it is not really a choice in most services today. Sites having WORKING webauthn are so rare that I literally mentioned it on my work Slack 2 days ago when I set one up at Target and it worked.
- cantrecallmypwd 2y agoI prefer Authy for most TOTPs, although regular Bitwarden supports Steam and Blizzard codes too and some TOTPs formats that it refuses to import.
- egamirorrim 2y agoYet another authenticator that I can't run on desktop
- blackeyeblitzar 2y agoDoes this have lock in like Authy, where it’s not possible to export the codes? Does it not work on desktop since the page says iOS and Android? And isn’t it a bad idea to use both the password manager and Authenticator from the same company?
- deleted 2y ago[deleted]
- RandyOrion 2y agoBitwarden app itself already integrates two-factor authentication code support. I use the app on both PC (chromium extension) and phone, and I'm happy about it.
- deleted 2y ago[deleted]