Bitwarden Authenticator is a standalone app that is available for everyone, even non-Bitwarden customers.

In its current release, Bitwarden Authenticator generates time-based one-time passwords (TOTP) for users who want to add an extra layer of 2FA security to their logins.

There is a comprehensive roadmap planned with additional functionality.

Available for iOS and Android

  • @Evotech
    link
    English
    67 months ago

    I’m not putting my totp with my password, same as I’m not putting my password with my email (proton)

    • Rolling Resistance
      link
      English
      97 months ago

      It’s a separate app with no sync to Bitwarden accounts.

      • @Evotech
        link
        English
        27 months ago

        Still, I bet they share a lot of the same backend and personell.

    • @[email protected]
      link
      fedilink
      English
      37 months ago

      And seemingly reading beyond the headline is also not your thing.
      This is a separate app unconnected to your bitwarden account…

    • pitninja
      link
      fedilink
      English
      3
      edit-2
      7 months ago

      Exactly, from a security perspective, it’s a bad idea to put 2 factor tokens together with your passwords. You effectively eliminate the security benefit that 2 factor provides if you do because if people get into your password manager, they have everything they need to access your accounts. The only people it “helps” having it all in one app are people who don’t understand the purpose of 2 factor and just see it as an inconvenience when services force it on them. Even though I use BitWarden for passwords, I don’t think that I’ll be changing from Aegis to BitWarden’s stand-alone authenticator because Aegis is doing its job nicely.

      • @[email protected]
        link
        fedilink
        English
        3
        edit-2
        7 months ago

        That’s also part of why I’m against the new passkeys. I think passkeys could replace either passwords or tokens, but not both.

      • million
        link
        English
        17 months ago

        It really depends on your threat model. It’s not a one size fits all thing.

        For instance in some threat models you shouldn’t have TOTP auth and passwords on the same device, let alone the same app, but the vast majority of people are not going to carry two devices because of how inconvenient it is.