Only for 2fa?

Reply to this note

Please Login to reply.

Discussion

No

Okay, thanks.

Storing 2fa in the same vault as passwords kind of defeats the purpose of 2fa in my opinion.

Using an offline authenticator with encrypted backups is a better solution?

If you have your password manager also installed on your phone, you gain nothing by keeping it separate.

It still mitigates threats like brute force attacks and password leaks.

Keep in mind, I have this 2fa setup for most (irrelevant accounts). For serious stuff I use the only real 2fa: a security key like a yubikey.

Sure, but if you're exposing your selfhosted bitwarden online, I still think a separate offline 2fa is more safe.

I'm not exposing it online as that would be crazy and suicidal.

Behind wireguard ONLY.