Post #1334712
2026-04-12 16:37 UTC
While having them grouped together in bitwarden creates a single point of failure, it does not undermine the value of TOTP too much.
TOTP being about having two separate parts of the auth process is not its whole application. What TOTP is about is having a part of your auth that is One-Time-use, so even if your password got leaked/hacked/intercepted it is worthless to an attacker.
Replies (1)
-
@steel_for_humans@piefed.social 2026-04-12 16:46
My Bitwarden and Proton Pass also require Yubikey to be present when logging in on a new device.