Don't store TOTP in Bitwarden for your online accounts (2022)
prezu.ca
prezu.ca
TOTP in Bitwarden (or 1Password or KeePass) is an upgrade over SMS authentication in terms of both security and convenience.
For most people, TOTP in a dedicated app is not actually much more secure:
1. They could lose the device. Without a backup, they're suddenly unable to login to their accounts. 2. Their device may not be well secured, e.g., either not requiring auth to unlock it or only having a 4 digit PIN. 3. They're likely logging into accounts on their phones and have the password manager and TOTP app on their phones as well. 4. If the TOTP app has backups, then it's vulnerable. 5. Such a user may be less likely to use 2FA in a given app because it's less convenient.
If you secure your devices with long alphanumeric passwords, secure your password manager with U2F / WebAuthn and an even longer alphanumeric pass phrase, and consistently enable TOTP 2FA, then you'll be more secure than the person who either uses it less consistently or who uses it on device
Yes, you would be more secure if you used it consistently AND had 2+ dedicated devices for your TOTP codes (your main device and at least one backup). But let me propose an alternative: do that just for your most critical accounts, but use your password manager's TOTP solution for everything else.
Which dedicated device would I recommend for storing your TOTP codes? The same one I recommend for U2F, the Yubikey 5 series (specifically the Yubikey 5C NFC). It can store up to 32 codes, which for 99% of people is more than enough for all of their critical accounts.
It's the same with any password manager. The issue is, after someone somehow had one peek at the decrypted data, they have all the TOTP seeds they need so they no longer care.
The article makes a similar point:
>> Among the people I’ve “interrogated” about sufficiently securing their online accounts were few who proudly said they’ve adopted a Password Manager and… they’ve copied their favorite password that they’ve been reusing all over the place into the Password Manager. And now they use the Password Manager’s web browser extension to paste the same password into each login form. Well, the only thing they’ve gained is a false sense of security.
>> However, if they do add a 2nd factor of authentication, even if that’s a TOTP managed by the same Password Manager, they do end up in a much better place. Now, looking back at the attack scenario I described above, their leaked password is not enough to log into other online accounts. Yes, they are still vulnerable to a scenario where their Password Manager account gets popped and the TOTP secrets are revealed. But still, their security posture has improved a lot!
FIDO2 and FIDO U2F are phishing-resistant, but almost nobody implements them, preferring security theater, and even when they do, not correctly (e.g. PayPal only allowing you to use one key, so if it gets broken or lost you are SOL).
But it's not; the author's point is just that putting your MFA token into the same place as your other passwords defeats some of the purpose of "multi-factor" authentication in the first place, since a breach of your password manager gets the attacker both factors.
So, nothing in particular for Bitwarden users to worry about, just general OpSec advice.
For super important stuff, such as email accounts, I use an external authenticator. For medium important stuff where I want a bit of extra security (or I’m forced to use 2FA when I don’t want to), I store it in the password manager.
If I'm using a long random password generated by a password manager, are these attacks realistic?
> phishing / MITM attacks
But if they can phish or otherwise capture my password, can't they just as easily phish or capture my one-time code?
> (or I’m forced to use 2FA when I don’t want to)
IMO, this is the only actual use-case, and it sucks because it adds additional login friction for absolutely no reason. If you want to ensure I'm using a strong password, generate the password for me as a condition of disabling 2FA.
Most likely no. But some people refuse to use such passwords, even when using password managers. Also it was only a few years ago Sony was caught storing passwords in plaintext so… Unless you trust the service is hashing and salting your password, MFA can be a good idea.
> But if they can phish or otherwise capture my password, can't they just as easily phish or capture my one-time code?
The TOTP lasts ~30 seconds. So the attack needs to occur in real-time (opposed to a form that just captures information). Can this happen? Absolutely. But it still raises the bar for the attack.
But yeah I agree, forced 2FA is infuriating.
Though that site is likely also storing the TOTP shared secret in plaintext, beside the password, making it pretty much pointless. If the site itself is compromised, it's hard to come back from that.
Pretty much the best thing you can do is never re-use passwords across sites.
It also has limited benefit against brute force attacks since it's essentially just a few extra numbers added to the password (although that certainly helps).
It does provide a defense against leaked previously passwords, and keyloggers if they aren't immediately used.
I'd love to be corrected if this isn't the case though.
EDIT: Totally forgot - it also protects you if your password manager is breached, assuming you don't store it in the password manager
It helps against brute force attacks but how much it helps depends on the service. If your service prompts for a 2FA code when provided with an incorrect password, then it helps a lot. If an attacker receives confirmation that they have a correct password before needing to enter the 2FA code, then it helps less.
This assumes a sophisticated attack, which is absolutely possible (I’ve even seen it happen), but is less likely than a form that just captures information. In any case, in the attack you describe, storing the TOTP externally doesn’t provide any additional protection over storing it within the password manager.
> EDIT: Totally forgot - it also protects you if your password manager is breached, assuming you don't store it in the password manager
Yeah that’s the entire point of the article. But managing TOTP separately can be a bit painful. So I’m saying that if you want a bit of additional security without any inconvenience, there are still benefits to storing a TOTP in your password manager opposed to having no MFA at all.
I wanted to make sure the limitations were pointed out that TOTP doesn't itself protect against sophisticated MITM/phishing attacks which a lot of people I've met thought.
But it absolutely provides some level of protection against unsophisticated attacks, and it's still helpful even inside your password manager.
And my Bitwarden Vault is hosted on a server I own. If it gets breached, I'm in deep trouble regardless.
However it is a second defense enforced by process/code alone (which can be turned off if you have access to the source). It doesn't effect the way your password is stored on the server, in the event of a leak or hack TOTP provides no brute force benefit.
As true as this is, it's because TOTP often breaks the spirit of MFA. Password-only logins where a password manager does the form filling are frictionless. Adding TOTP MFA to every single login—even a login from a known browser, where an existing cookie and browser fingerprint would serve adequately as the second factor—regresses UX back to the point before password managers got involved. Back when I was typing passwords, I didn't have to pull out my phone and look them up first.
The TOTP seed has just become the real password, because your "password" password isn't good enough. Security is hard, so service providers assume you're going to screw it up, and they make authentication suck.
For example, some social media accounts don't support multiple users and so you either need a shared company phone for 2FA or you can put TOTP into the company password manager along with the password. I see no workaround for this. I guess you could have a separate company 2FA system that is shared like let's say you use 1pass for passwords and bitwarden for 2FA, but still, local machine exploit will gain access to both.
I find my biggest problem with TOTP is not losing the damn things when changing phone, so I want them to be stored somewhere that get synced between devices.
Being able to store a TOTP in my password manager allows me to have a shared account still use 2FA - and provided all parties also have 2FA on their Bitwarden accounts I think this is a pretty secure system and much preferable to one party having TOTP and everyone else needing to email or message them to get the code. Especially considering that as the number of "Hey can you send me the code to log in real quick" messages the 2FA holder gets goes up, the likelihood they get complacent and just start automatically responding could also create a threat vector.
Except TOTP secret in password manager is the same factor as the password (both being the password manager), so you don't get 2FA
Sure you can have a yubikey for your 2FA, but then you need a backup in case you loose it or break it, and you need to store that backup somewhere (physically or virtually), and you need to trust / secure that location, or encrypt the data, but then you need another secret to decrypt it, and you need a backup of that too, and so on.
I don't see any way to break that Russian Doll effect. Any suggestions?
Pick a good password for the backup and recall it every morning and at random points in the day; the intent is to make you remember it even under stress. Also have it printed out or written somewhere in a place that no one will notice/find - say as a scribbling in your sketchbook or printed at the bottom of a document in your file folder. If you're creative you can even hide it on a sticker inside an object or so forth. No one will know that the string there actually is your password, and if you want you can split it among different pages/etc.
Now if only banks would implement proper two-factors...
Though what's with all the recent criticism of Bitwarden? It's by far the best solution for personal security that you can also self-host and its code is OSS.
do use BW for TOTP, but then add a hardware key. Boom. Better security and, just as important, only one site to tell about your yubikey (managing FIDO2 hardware across several websites puts it in now-you-have-two-problems territory)
The biggest problem by far is that people still use the same password everywhere, and no amount of yelling at them for the past 20 years seems to be working, so the only solution is to declare passwords as mostly broken and force people to use TOTP. That’s effectively how most sites are using it anyway. Using this approach, you now have a probably weak password of a certain length, and then a guaranteed random password of 6 digits that expires every 30 seconds. The brute force window is essentially closed at that point.
This approach also reconciles the idea that a TOTP secret must be tied to a device, instead of a person. I’m pretty security conscious and can put up with a lot of shenanigans to be more secure, but the insistence of TOTP apps to not allow backup or transfer of secret keys is just too much for me. I can’t imagine any regular user putting up with that, and the result is the help desk has to deal with many requests to remove devices when someone gets a new phone.
With the threat model redefined to force the use of unique passwords, it makes it far more acceptable to store TOTP secrets in password managers.
Nobody wants to carry around an extra thing on their keychain just so they can login to stuff. They already have a phone, and every other thing that uses physical keys is currently in the process of moving to using apps on phones. Just like Yubikeys, they will be used for some high security applications, but will not gain general acceptance by users.
To me, that feels like the missing piece in my mostly-offline way of managing credentials and backing them up - I could throw the KeePass database and this TOTP database (presumably both protected by passwords) in a VeraCrypt container (also encrypted) or something similar, put that on an SD card and then store it somewhere in case of hardware failures or other factors like that.
Personally I think that TOTP is great and while there are plugins for KeePass for example, most people will opt for using various apps which don't always let you fully be in control of your files. As for cloud options - they are easy to use, of course, but personally that feels like a major risk, which the LastPass breach somewhat confirmed.
Overall, Aegis is my to-go open-source alternative to Authy.
I'd with multi-platform password managers would have two different vaults, where one is for general computing and another is encrypted differently and only available for trusted always-available devices (phone, smart watch or something like that), and OTP seeds could be moved there and become accessible only to such trusted devices. Then, the password manager should be able talk to itself on those devices and ask them to provide an OTP (depending on user preferences, with or without on-device confirmation), so the seed isn't available but the current OTP value is conveniently accessible. Tricky, complicated, but secure and convenient.
But that's ultimately a hack. The best one could hope for is WebAuthn eventually killing TOTP entirely.
For instance:
- to get into my gmail, you’ll need my password and TOTP.
- both the password and TOTP are stored in my password manager, so you need to unlock my password manager.
- to unlock my password manager, you need its password, and its 2-factor code.
- the password isn’t written down so you’ll need to know it
- the 2-factor code is only accessible on a device, so you’ll need one of my device.
- thus, to get into my email, you need both to know something and have something of my belonging.
That is of course based on the presumption that you trust the password manager’s implementation.
If you've managed to get into my password manager, it means you must have gained access to my machine whilst it was unlocked (and my password manager was unlocked too). If that's the case, you already have access to live sessions to most of the things stored in my password manager.
Essentially, if you have access to my password manager, I am completely fucked anyway, whether my OTP codes are in there or not.
In theory some sort of HSM like a Yubikey could do it, but in practice I'm not aware of any password managers that use that feature (other than maybe one or two obscure KeePass plugins?)
Similarly, that's why 1Password is more secure than BitWarden or LastPass, because it has a separate "master key file" that's required in addition to your password to set up your vault.
But breach is ultimately a separate issue from authentication.
It's the fundamental security threat model that all password managers are built under, even LastPass. They all are built to ensure that your passwords are secure even if the password manager's cloud service is compromised.
The article makes sense and I see the flaw in keeping them both in one place. Wish I'd thought that through.
Related: did you know you can use multiple apps for that TOTP code? Just scan the QR code in App A, then scan the exact same code in App B. That + Yubikey 5's TOTP app means two identical copies of the codes on two different media. Approaching a decent backup scheme.
Then I moved to Yubikey, which I also love. I don't see the point in using Google when there are good alternatives :)
IMO it makes sense to have most of your TOTPs in Bitwarden - anything that isn't critical. The reduced friction means you're more likely to enable TOTP 2FA for every account that you can - net increase in security compared to not having it at all.
For your critical accounts, I recommend securing them with your Yubikey via U2F / WebAuthn if possible. If not, then use your Yubikeys to store the TOTP codes. If you need/want a better backup than a second device, you could consider literally writing them down or backing them up into a Veracrypt encrypted container. You could also use an open-source, local-only TOTP app like andOTP/Aegis on Android or Tofu/OTP Auth on iPhone.
If your threat model shows this to be a bad idea, you obviously need to do what is best for you. But for the typical person, this post can be easily ignored.