TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Bitwarden Authenticator

198 pointsby pil0u3 months ago

29 comments

ripped_britches3 months ago
I have used Bitwarden for a few years happily, but have been really annoyed at the UI changes in the chrome extension<p>Not only does it unnecessarily jar me out of my memorized places to click, but it also just takes 2 clicks to copy a password instead of 1. Seems like a small deal but it is genuinely a bad UI.
评论 #43154598 未加载
评论 #43154619 未加载
评论 #43155994 未加载
评论 #43156969 未加载
评论 #43160134 未加载
评论 #43209983 未加载
评论 #43155647 未加载
评论 #43156743 未加载
bramhaag3 months ago
I have been using Aegis [1], a FOSS (GPLv3) TOTP authenticator app, for the past years.<p>It supports:<p>- Local encrypted backups. You can sync these to where ever you like on your own terms. I automated uploading mine to my local NextCloud instance.<p>- Importing from other authenticator apps, so you can easily migrate.<p>- Exporting entries so that you are not vendor locked (<i>cough cough</i> Authy).<p>- Customization.<p>- No mandatory cloud bs, LLM integration, tracking, ...<p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;beemdevelopment&#x2F;Aegis">https:&#x2F;&#x2F;github.com&#x2F;beemdevelopment&#x2F;Aegis</a>
评论 #43155111 未加载
评论 #43155067 未加载
layer83 months ago
It doesn’t support syncing between devices.<p>An alternative is Ente Auth: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40883839">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40883839</a><p>Edit: Since there seems to be some confusion, this submission is about Bitwarden Authenticator, a free mobile app for TOTP, not about the Bitwarden password manager, which does support syncing, and which in the paid Premium plan also includes an authenticator.
评论 #43154144 未加载
评论 #43155254 未加载
评论 #43154307 未加载
评论 #43153922 未加载
评论 #43154154 未加载
评论 #43154147 未加载
评论 #43153929 未加载
评论 #43153961 未加载
sepositus3 months ago
&gt; In this initial release, your data will be backed up through the mobile operating system&#x27;s backup services. Please make sure your device is turned on and configured for backups. Bitwarden Authenticator data is included in the OS backups and will be restored with them.<p>At least it&#x27;s not defaulting to their own cloud service backend. This has always been my problem with these types of apps. Although, I&#x27;m not sure I fully understand the above description. I&#x27;m guessing if you have an iPhone with iCloud backup enabled, it means data is backed up to iCloud.
评论 #43153640 未加载
评论 #43153995 未加载
评论 #43153943 未加载
评论 #43153926 未加载
评论 #43153599 未加载
mdevere3 months ago
Big fan of Bitwarden, albeit you are putting a single point of failure on all of your secure info.<p>I&#x27;d love to know what others do to maximise both convenience and security.<p>For two-factor authentication, I wouldn&#x27;t use the same service for both layers. Seems daft to use Bitwarden as both the password keeper and the TOTP provider. Not sure if that&#x27;s a cryptographically coherent view, but hey.
评论 #43154023 未加载
评论 #43153904 未加载
denkmoon3 months ago
Doesn&#x27;t appear to have any way of exporting 2FA tokens?<p>I _very narrowly_ dodged being locked in to authy by having tokens in there that couldn&#x27;t be exported, and authy is a steaming pile of... Never again will I be foolish enough to not maintain ownership of the actual 2fa tokens my codes are generated from.
评论 #43154484 未加载
stavros3 months ago
I&#x27;m confused, doesn&#x27;t BitWarden already include this functionality? I&#x27;ve been using it for years, have they split it out into a separate app?<p>I tend to use Aegis for the two services&#x27; TOTP codes that I don&#x27;t put into BitWarden.
评论 #43153722 未加载
评论 #43153864 未加载
评论 #43153721 未加载
makeitdouble3 months ago
Is it standard for Bitwarden to have absolutely no mention of a any plan to also build a PC app ?<p>I can&#x27;t find any.
评论 #43153692 未加载
评论 #43153962 未加载
kyriakos3 months ago
At some point Microsoft authenticator decided that 2fa from a smartwatch shouldn&#x27;t work (that happened when they introduced the 2 digit number verification which could still work fine on a watch). I have yet to find a replacement for that feature. If anyone figure it out please let me know!
marcosscriven3 months ago
How does this compare to Authy? I use Bitwarden and have been very frustrated with their UI changes.
评论 #43153966 未加载
评论 #43156749 未加载
评论 #43155622 未加载
评论 #43153825 未加载
jz103 months ago
I just literally spent a week transferring all my authy keys to Bitwarden&#x27;s somewhat hidden OTP generator feature. nice to see they finally made a standalone app. Now I&#x27;m gonna find out if both are integrated..... (I really hope so)
ViVr3 months ago
I&#x27;d like to see them add support for including attachments in your Bitwarden exports before i go putting any more critical data into their ecosytem.<p>It has been a feature request for close to 6 years now: <a href="https:&#x2F;&#x2F;community.bitwarden.com&#x2F;t&#x2F;allow-attachments-to-be-exported-when-using-export-data&#x2F;835" rel="nofollow">https:&#x2F;&#x2F;community.bitwarden.com&#x2F;t&#x2F;allow-attachments-to-be-ex...</a>
评论 #43153933 未加载
itsthecourier3 months ago
I was a LastPass client then they got hacked and I moved to bitwarden. feel better with their app integration and it feels good.<p>yet I wouldn&#x27;t use their 2fa app, just because if they get hacked at some point I don&#x27;t want passwords and 2FA stored with the same company<p>doing great with authy in that front
blackeyeblitzar3 months ago
Does this have lock in like Authy, where it’s not possible to export the codes? Does it not work on desktop since the page says iOS and Android? And isn’t it a bad idea to use both the password manager and Authenticator from the same company?
hedora3 months ago
The “An Error Occurred” database corruptions last year convinced me I can’t trust bitwarden any more.<p>Any suggestions for something I can host at home? It needs mac, linux and ios clients and (unlike bitwarden) must gracefully handle the server being unavailable.
评论 #43154861 未加载
评论 #43154873 未加载
yumraj3 months ago
I had exported my tokens out of Authy when they had killed the desktop version, and imported into KeypassXC.<p>I find keypassxc which I use for managing passwords and now TOTP to be the best option for me.<p>I still use Authy on mobile but having an offline backup is great.
sneak3 months ago
TOTP is bad. TOTP is phishable. Stop using or promoting TOTP.<p>We have modern authentication called WebAuthn, supported by Bitwarden proper as well as physical security keys and iOS’s native password manager. Use it.
评论 #43159810 未加载
评论 #43157429 未加载
jackhalford3 months ago
Funny this pops up today, I’ve finished migrating form KeepassXC to a self hosted vaultwarden, the official bitwarden apps and briwser extension are super well made, so good so far with the switch.
RandyOrion3 months ago
Bitwarden app itself already integrates two-factor authentication code support.<p>I use the app on both PC (chromium extension) and phone, and I&#x27;m happy about it.
cantrecallmypwd3 months ago
I prefer Authy for most TOTPs, although regular Bitwarden supports Steam and Blizzard codes too and some TOTPs formats that it refuses to import.
haswell3 months ago
I’ve been using the “OTP Auth” app by Roland Moers since hearing about it on Steve Gibson’s Security Now podcast.<p>Extremely happy with it.
NewJazz3 months ago
How would this work on a degoogled android? I just use freeotp+ and have backup codes in case I lose the device.
评论 #43153746 未加载
评论 #43153671 未加载
Paul-Craft3 months ago
Okay. So? HOTP and TOPT are so trivial to implement, you can even use a C64[0] as your 2FA device. Here&#x27;s my anti-FAQ[1] to their FAQ:<p>---<p>### <i>TOPT ANTI-FAQ</i><p>1. Want a guide to implementing time-based passwords in your app? Here you go: <a href="https:&#x2F;&#x2F;www.freecodecamp.org&#x2F;news&#x2F;how-time-based-one-time-passwords-work-and-why-you-should-use-them-in-your-app-fdd2b9ed43c3&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.freecodecamp.org&#x2F;news&#x2F;how-time-based-one-time-pa...</a><p>2. What was that? You want to do it in Typescript? Okay, here you go: <a href="https:&#x2F;&#x2F;www.npmjs.com&#x2F;search?q=totp" rel="nofollow">https:&#x2F;&#x2F;www.npmjs.com&#x2F;search?q=totp</a><p>3. Want to do it in Python? Unfortunately, you only have 275 choices: <a href="https:&#x2F;&#x2F;pypi.org&#x2F;search&#x2F;?q=totp&amp;o=-created" rel="nofollow">https:&#x2F;&#x2F;pypi.org&#x2F;search&#x2F;?q=totp&amp;o=-created</a><p>4. How about on an Arduino? <a href="https:&#x2F;&#x2F;github.com&#x2F;lucadentella&#x2F;TOTP-Arduino">https:&#x2F;&#x2F;github.com&#x2F;lucadentella&#x2F;TOTP-Arduino</a><p>5. Fuck it, we&#x27;ll do it ~~live~~ in Emacs!<a href="https:&#x2F;&#x2F;www.masteringemacs.org&#x2F;article&#x2F;securely-generating-totp-tokens-emacs" rel="nofollow">https:&#x2F;&#x2F;www.masteringemacs.org&#x2F;article&#x2F;securely-generating-t...</a><p>Y&#x27;all get the point by now, I&#x27;m sure.<p>---<p>[0]: <a href="https:&#x2F;&#x2F;www.gadgetany.com&#x2F;news&#x2F;now-the-commodore-64-is-a-two-factor-authentication-device&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.gadgetany.com&#x2F;news&#x2F;now-the-commodore-64-is-a-two...</a><p>[1]: &quot;Anti&quot;-FAQ, because I&#x27;d like to discourage people from wasting brain cycles on thinking that a time-based authenticator app is something worth announcing.
beebaween3 months ago
Do I still have to pay extra to use a yubikey?
Lord_Zero3 months ago
Are we all off the 2FAs train now?
samstave3 months ago
no.<p>Zero trust, and that it slides auth horizontally to other untrusted flows...<p>Like literally walk an LLM through my data path?
bootcat3 months ago
why can&#x27;t this be in the same app,
egamirorrim3 months ago
Yet another authenticator that I can&#x27;t run on desktop
yoyohello133 months ago
So I’ve been a happy Bitwarden subscriber since about 2020. I originally picked it because it seemed like a good compromise between open source options like keepassxc and something less trustworthy like one password.<p>I haven’t really be paying much attention to Bitwarden lately, but I’ve heard they’ve taken vc&#x2F;got bought out or something. So for those more in the know, is it time to start migrating? Or does Bitwarden still seem like it’s on a good path?
评论 #43153812 未加载