this post was submitted on 01 May 2024
512 points (97.4% liked)

Technology

57473 readers
4053 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Bitwarden Authenticator is a standalone app that is available for everyone, even non-Bitwarden customers.

In its current release, Bitwarden Authenticator generates time-based one-time passwords (TOTP) for users who want to add an extra layer of 2FA security to their logins.

There is a comprehensive roadmap planned with additional functionality.

Available for iOS and Android

you are viewing a single comment's thread
view the rest of the comments
[–] Concave1142@lemmy.world 19 points 3 months ago (13 children)

Correct me if I am wrong, but the Bitwarden client itself already does this. I store several of my TOTP's in my self hosted Vaultwarden/Bitwarden install.

[–] aseriesoftubes@lemmy.world 0 points 3 months ago (8 children)

You’re right, it does. This is a head-scratcher.

I guess they already had the TOTP code written, so creating a standalone app was trivial, but what’s the point?

[–] ma11ie@lemmy.one 32 points 3 months ago (2 children)

Security-wise it’s not a good idea to keep passwords and 2FA codes in the same client as it then becomes a single point of failure. A standalone authenticator app resolves that as long as it’s not unlocked with the same master password. A standalone app also opens a venue for non-BW customers to get on their platform.

[–] EngineerGaming@feddit.nl 2 points 3 months ago* (last edited 3 months ago) (1 children)

Would it count if the application is the same but all the TOTP is handled by a different database with a different passphrase?

[–] Evotech@lemmy.world 1 points 3 months ago

Depends on how they got broken

[–] Reawake9179@lemmy.kde.social 2 points 3 months ago

It's not a good idea to keep both on the same device, but i wouldn't use it at all if it was a struggle

load more comments (5 replies)
load more comments (9 replies)