this post was submitted on 09 Apr 2024
503 points (92.7% liked)
Technology
59207 readers
3307 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
When vaultwarden supports this I’ll play ball. If I don’t have control over my authentication methods, then they aren’t my authentication methods.
Do you really think it's a good idea to store your password, TOTP and pass key in one place?
Yes, as long as that place is only accessible by a physical passkey (such as a Yubikey). The risk is miniscule and the convenience is 100% worth it.
I'm actually not sold that I should be putting all my keys in a single password manager like Bitwarden.
To my bank? No. To a Lemmy account? Yep.
Treating social media accounts as irrelevant is fine as long as none of your real life friends associate with you on the same platform. Once that's the case, scammers can take over your platform and send messages to your friends telling them you're stuck and need money or other sorts of things that sound ridiculous but work all the time.
I am not treating them as irrelevant, hence a password manager. But I am not treating it as fort knox. Most of my real-life friends probably don't even go that far.
I personally settled on having TOTP in the same application but in a different database.
Bitwarden does, not sure about the self-hosted version.
Still waiting for the mobile app. Maybe the firefox addon would work, but would prefer the app
Vaultwarden has supported pass keys for a while. The client app does all the hard work in this pattern.