upvote
Having your passwords and 2FA with the same provider carries some risk. If someone can access your Bitwarden account they will have full access to all your accounts.
reply
I always feel conflicted with this.

Using my password manager to store 2FA codes is convenient, but it adds a layer of indirection if they are elsewhere.

But if you've compromised my password manager, you almost certainly have enough access to my machines to get to the alternatives.

reply
What's your plan when you lose access to Bitwarden?

What happens when your Bitwarden gets compromised?

reply
> All 2FA runs through it

I hope that isn't true, because I sure can't think of a good way to use Bitwarden's TOTP as 2FA for Bitwarden! :)

reply
FIDO2 USB Security key -> Bitwarden (With master password) -> Every other 2FA method

I have 3 FIDO2 USB Security keys, One I carry with my persons at all times, one that stays with my main machine at all times and an offsite backup that is sitting in a friend's server, if my house burns down, I can either physically collect the key or use USB-IP to authenticate back into bitwarden and enroll a new key. (Actually all 3 are at home right now but that's ok)

My phone is logged into Bitwarden so even then I can recover my passwords and data in case of a serious incident immediately.

Even if both my house and my friend's house burn down at the same time, I can still recover my data from my phone unless my phone is left in the house, all of which to say I still have the recovery phrase written down in a box somewhere in a different country

reply