Hacker News new | ask | show | jobs
by aryonoco 823 days ago
There are different ways to avoid this.

Nearly all of my 2FA are in Bitwarden, because it's just so damn convenient. But my Bitwarden itself uses YubiKey as 2FA.

Since I adopted this setup last year, it's been the best if both worlds for me.

2 comments

>my Bitwarden itself uses YubiKey as 2FA.

I want to do the same but haven't switch yet.

- Is the YubiKey USB-C? Is the connector type an issue when plugging it into various computers?

- Where do you keep your YubiKey (plugged into your laptop, on a keychain, somewhere else).

- How do you open your vault on mobile?

- Do you have a backup YubiKey somewhere in case you lost the main one?

The whole concept of yubikeys bothers me. If it is lost, broken, or stolen, access to everything it protected is effectively gone. Same for SMS if you have an eSIM and your phone is lost or destroyed (as happened to me recently, and was a nightmare). TOTP synchronized to multiple devices seems to be the only way to have MFA while protecting oneself from getting locked out. I'm open to being convinced otherwise.