this post was submitted on 01 May 2024
119 points (97.6% liked)

Privacy

31882 readers
644 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
119
deleted by creator (bitwarden.com)
submitted 6 months ago* (last edited 2 months ago) by ForgottenFlux@lemmy.world to c/privacy@lemmy.ml
 

Bitwarden Authenticator is a standalone app that is available for everyone, even non-Bitwarden customers.

In its current release, Bitwarden Authenticator generates time-based one-time passwords (TOTP) for users who want to add an extra layer of 2FA security to their logins.

There is a comprehensive roadmap planned with additional functionality.

Available for iOS and Android

top 21 comments
sorted by: hot top controversial new old
[–] jonwyattphillips@lemmy.ml 8 points 6 months ago (1 children)

No import? No scan qr code from image?

[–] lemmyvore@feddit.nl 8 points 6 months ago

No export either, just Google Backups.

Also the feature roadmap looks bad. They don't plan to add any of the features you'd expect from a standalone 2FA app, they just plan to sync with Bitwarden and eventually integrate completely with Workforce. So it looks like a bait and switch with no way to get your codes out.

[–] Gargari@lemmy.ml 8 points 6 months ago (2 children)
[–] Xy_lemmy@lemmy.ml 2 points 6 months ago

I wish it had a desktop app. Id switch to it instantly.

[–] PrivacyWayFinder@lemmy.world 1 points 6 months ago

Hell yeah, I find Mauth as ditto to it.

[–] filister@lemmy.world 5 points 6 months ago (1 children)
[–] folkrav@lemmy.ca 43 points 6 months ago (1 children)

What’s wrong with alternatives?

[–] lemmyvore@feddit.nl 4 points 6 months ago (1 children)

Nothing, but this particular alternative is pretty awful. Literally zero features besides TOTP code generation, and they don't plan to make it better. I really don't understand why this app exists.

The only people who would possibly care about it is existing Bitwarden users who want to use it to hold the code for their Bitwarden account independently from account. But they say they plan to add Bitwarden sync to it so?....

Honestly it just looks like a super lazy attempt to draw people to Bitwarden (assuming it doesn't turn into a sleazy attempt of holding codes captive with no way to get them out).

[–] fushuan@lemm.ee 1 points 6 months ago

You can have synced authentication right now on their password manager, so unless they remove features I don't think they will remove the waybto export codes from bw.

[–] archer@lemmy.ml 5 points 6 months ago* (last edited 6 months ago) (3 children)

Is there a FOSS 2FA app that syncs between Linux, MacOS and Android (using a self-hosted Server)?

[–] snoqualmieowl@lemmy.world 3 points 6 months ago
[–] madcaesar@lemmy.world 2 points 6 months ago

Aegis? I use that

[–] Sebbe@lemmy.sebbem.se 1 points 6 months ago (1 children)

I don't know about Mac OS but Bitwarden syncs just fine to my Android and Linux devices from my server.

[–] archer@lemmy.ml 1 points 6 months ago (1 children)

Are you talking about the Bitwarden app mentioned here for 2FA specifically (because apparently it's not very good) or the Bitwarden/Vaultwarden (backend) password managers (which are great)?

[–] Sebbe@lemmy.sebbem.se 2 points 6 months ago

Bitwarden and Vaultwarden

[–] fluckx@lemmy.world 1 points 6 months ago (2 children)

Weird. If I copy the TOTP code from bitwarden into their 2fa app I get different codes. Not even after a rotation ( one isn't ahead of the other ). That doesn't seem right :/

[–] Mountaineer@aussie.zone 4 points 6 months ago (1 children)

TOTP is a defined standard, specifically RFC 6238.
But I still have 3 different apps on my phone so that I can get on to various customer VPNS. 🤷‍♂️

[–] lemmyvore@feddit.nl 6 points 6 months ago

Because they use proprietary algorithms not TOTP.

[–] fluckx@lemmy.world 1 points 6 months ago (1 children)

Wait - so far its only the Microsoft MFA code that does it.

[–] lemmyvore@feddit.nl 1 points 6 months ago* (last edited 6 months ago) (1 children)

Microsoft MFA has the option of being set up (by admins) with either standard TOTP or with their proprietary algorithm.

If the admins for the realm you're trying to use have chosen the proprietary one you need to use the Microsoft Authenticator app. Regular TOTP generators will accept the code but the code they make won't work.

Can the regular Bitwarden generator make good codes? If so, it means they figured out (or were told by Microsoft) how the proprietary algorithm works. But since this standalone app is open source they couldn't add that algorithm to it.

[–] fluckx@lemmy.world 1 points 6 months ago

My main issue is that if I add the bitwarden TOTP secret string manually multiple times its generating different codes between the entries. Which seems like something that shouldn't happen.

It is a different format to the other ones I've got though.

Fuck Microsoft authenticator though. Had to restore it to a new phones once and if you don't do it on initial startup you can't restore it at all. Good thing I had a secondary app that still had them. Absolute garbage.